# e-discovery.uk PDF library > Every downloadable brochure, guide and checklist published by E-Discovery.UK, the eDiscovery arm of Computer Forensics Lab. UK disclosure practice under CPR Part 31 and Practice Direction 57AD, forensic collection, processing, hosted review on Relativity, and production. Library index: https://e-discovery.uk/library Atom feed of new and updated guides: https://e-discovery.uk/library-feed.xml Sitemap: https://e-discovery.uk/sitemap.xml Citation and reuse policy: https://e-discovery.uk/ai.txt Documents: 163 Generated: 2026-09-22T18:01:11.523Z Citation format: E-Discovery.UK - - ## Documents ### The Complete Guide to eDiscovery and eDisclosure Page: https://e-discovery.uk/library/complete-guide-to-ediscovery-and-edisclosure PDF: https://e-discovery.uk/__l5e/assets-v1/a5b9f353-eb70-4807-98ff-0087d8627ef6/complete-guide-ediscovery-edisclosure.pdf Category: Guide Published: 2026-09-20 Pages: 74 Topics: Disclosure and CPR compliance, Forensic collection and imaging, Chain of custody and defensibility, US litigation support Keywords: eDiscovery, eDisclosure, CPR Part 31, PD 57AD, PD 31B, legal hold, Disclosure Review Document, technology assisted review, cross-border discovery, chain of custody A UK-first practitioner handbook on electronic disclosure for solicitors, barristers, in-house counsel, paralegals, investigators and litigation support teams. Part One sets out the vocabulary, the English rulebook, a topic by topic comparison with United States discovery and the ten stage lifecycle the rest of the guide follows. Part Two covers information governance and litigation readiness, when the duty to preserve arises, PD 57AD paragraph 4 step by step, hold notices and preservation letters, the evidence source map across eight source families, custodian tiers, control, and collection method, metadata, hashing and chain of custody. Part Three moves from data to disclosure: the processing pipeline and the settings that are really legal decisions, early case assessment, a seven step search method with hit reporting, the review protocol and quality control, technology assisted review and generative AI with the validation statistics and case law behind them, privilege and redaction, and production, inspection and authenticity. Part Four addresses special situations, documents held by non-parties, cross-border matters where US discovery meets UK data, data protection in disclosure including the Data (Use and Access) Act 2025, costs and proportionality, choosing technology and providers, and forums beyond the High Court. Part Five is the working toolkit: worked examples, fifteen recurring mistakes, red flags, when to involve a digital forensic expert, forty questions to ask the client, the opponent and the provider, suggested wording for preservation advice, hold notices and DRD entries, a master checklist, a fifty term glossary and a full reference list. Law stated at 20 September 2026. ### Crypto Assets: Investigation, Tracing, Attribution and Disclosure Page: https://e-discovery.uk/library/cryptocurrency-assets-investigation-tracing-attribution-disclosure PDF: https://e-discovery.uk/__l5e/assets-v1/850559c5-30ad-4dba-bff8-c7431fbbb82a/Crypto-Assets-Investigations-Tracing-Attribution-Disclosure.pdf Category: Guide Published: 2026-09-04 Pages: 72 Topics: Crypto asset investigations, Expert evidence and reports, Chain of custody and defensibility Guide 7 in the CFL Electronic Evidence Series, a legal and technical reference for practitioners in England and Wales who meet crypto assets in litigation, fraud investigations, insolvency, divorce and regulatory work. It explains what a blockchain record actually proves and what it does not, how transactions are traced across public ledgers, mixers, bridges and exchanges, and how an address or wallet is attributed to a real person through exchange records, device artefacts, seed phrase recovery and open source material. Later chapters set out preservation and seizure of wallets and keys, working with exchanges and custodians in and outside the jurisdiction, freezing and proprietary injunctions, Norwich Pharmacal and Bankers Trust relief, and the disclosure obligations that follow under CPR Part 31 and PD 57AD. The guide covers valuation and tracing of mixed funds, stablecoins, DeFi protocols and NFTs, the evidential standards a court expects of blockchain analytics output, and how to write and defend an expert report on crypto evidence under CPR Part 35. Chain of custody, hashing, documented provenance and ISO 17025 aligned laboratory practice run throughout, alongside worked examples, checklists and drafting points that a solicitor, in-house lawyer or investigator can apply directly to a live matter. ### Android Acquisition Logical File System And Physical Page: https://e-discovery.uk/library/android-acquisition-logical-file-system-and-physical PDF: https://e-discovery.uk/api/public/library/android-acquisition-logical-file-system-and-physical Category: Guide Published: 2026-09-02 Pages: 17 Topics: Forensic collection and imaging, Mobile and messaging evidence Keywords: android acquisition, android extraction, logical extraction, file system extraction, physical extraction, mobile forensics, digital forensics, android evidence, deleted data, mobile device, forensic report, acquisition method, e-discovery, disclosure This guide explains the three depths of Android data extraction: logical, file system, and physical. It details how the device dictates possible methods, the importance of integrity, and how to interpret reports. UK litigators will learn to choose, obtain, and defend appropriate acquisition depths for mobile evidence. ### Android App Data And Third Party Application Forensics Page: https://e-discovery.uk/library/android-app-data-and-third-party-application-forensics PDF: https://e-discovery.uk/api/public/library/android-app-data-and-third-party-application-forensics Category: Guide Published: 2026-09-02 Pages: 18 Topics: Mobile and messaging evidence Keywords: android app forensics, third-party app forensics, android data recovery, mobile forensics, app data analysis, sideloaded apps, cloned apps, dual apps, android app data storage, digital forensic expert, e-discovery android, mobile device forensics, app data interpretation, android evidence, digital evidence Android app data forensics requires understanding an open ecosystem, where each app is its own world. This guide details how apps store data, what openness adds, and how to inventory, recover, interpret, and attribute evidence from Android applications, including unexpected ones. ### Android Backups Local Google And Manufacturer Cloud Page: https://e-discovery.uk/library/android-backups-local-google-and-manufacturer-cloud PDF: https://e-discovery.uk/api/public/library/android-backups-local-google-and-manufacturer-cloud Category: Guide Published: 2026-09-02 Pages: 19 Topics: Mobile and messaging evidence, Cloud evidence Keywords: android backup, mobile forensics, digital forensics, google backup, manufacturer cloud backup, local android backup, android data recovery, android e-discovery, mobile phone evidence, deleted data, data preservation, forensic expert, electronic disclosure, disclosure, mobile device backup, android data Android phones generate several types of backups, none complete, each selective. These backups preserve phone contents at the moment they are made, surviving the phone itself. Understanding what each backup holds, what it leaves out, and how to access them lawfully is crucial for legal practitioners. ### Android Deleted Data SQLite And Unallocated Space Page: https://e-discovery.uk/library/android-deleted-data-sqlite-and-unallocated-space PDF: https://e-discovery.uk/api/public/library/android-deleted-data-sqlite-and-unallocated-space Category: Guide Published: 2026-09-02 Pages: 19 Topics: Mobile and messaging evidence, Deleted data and recovery Keywords: android deleted data, android data recovery, sqlite free space, unallocated space, mobile forensics, digital forensics, deleted data survival, file based encryption, trim command, data extraction depth, android evidence, deleted messages, forensic acquisition, mobile phone data, data preservation, electronic disclosure Deleted Android data often persists in SQLite free space and journals, recoverable until overwritten. Modern file-based encryption and TRIM significantly reduce the success of classic unallocated-space carving. Recovery depends on acquisition depth, device encryption, storage type, and prompt preservation. ### Android Encryption Secure Boot And Lock Screen Protections Page: https://e-discovery.uk/library/android-encryption-secure-boot-and-lock-screen-protections PDF: https://e-discovery.uk/api/public/library/android-encryption-secure-boot-and-lock-screen-protections Category: Guide Published: 2026-09-02 Pages: 18 Topics: Mobile and messaging evidence, Encryption and access Keywords: android encryption, locked android phone, secure boot, lock screen protections, mobile forensics, digital forensics, credential access, lawful access, cpr part 35, expert report, mobile handset, device encryption, android security, evidence recovery, digital evidence, forensic expert Modern Android phones are encrypted by default, with their security tied to the lock-screen credential and a hardware security chip. This guide explains how Android encryption works, the role of verified boot, lock-screen protections, and lawful access to locked devices, including common mistakes and technical limitations. ### Android Forensics The Fragmented Landscape Page: https://e-discovery.uk/library/android-forensics-the-fragmented-landscape PDF: https://e-discovery.uk/api/public/library/android-forensics-the-fragmented-landscape Category: Guide Published: 2026-09-02 Pages: 18 Topics: Mobile and messaging evidence Keywords: android forensics, mobile forensics, android fragmentation, digital forensics, mobile device forensics, android evidence, android acquisition, digital evidence, mobile phone forensics, android expert, cpr part 35, chain of custody, ediscovery, digital forensic expert, android phone, mobile handset, android device, forensic acquisition Android forensics presents unique challenges due to device fragmentation across manufacturers, models, and software versions. This guide details how these differences impact evidence acquisition and analysis, offering insights for UK legal professionals navigating mobile and messaging evidence. ### Android Location Fused Location WiFi And Cell Data Page: https://e-discovery.uk/library/android-location-fused-location-wifi-and-cell-data PDF: https://e-discovery.uk/api/public/library/android-location-fused-location-wifi-and-cell-data Category: Guide Published: 2026-09-02 Pages: 19 Topics: Mobile and messaging evidence Keywords: android location, fused location, wifi location, cell data location, mobile forensics, location accuracy, location evidence, digital forensics, expert report, cpr part 35, google location history, location data, android phone, location analysis, gnss, cell site analysis This guide explains how Android phones determine and store location data. It details the fused model, where location records reside, and how accuracy varies by source. It also covers common mistakes, technical limitations, and questions for effective analysis. ### Android Malware Stalkerware And Compromise Page: https://e-discovery.uk/library/android-malware-stalkerware-and-compromise PDF: https://e-discovery.uk/api/public/library/android-malware-stalkerware-and-compromise Category: Guide Published: 2026-09-02 Pages: 20 Topics: Mobile and messaging evidence, Cyber incidents and ransomware Keywords: android malware, android stalkerware, android compromise, mobile forensics, digital forensics, android security, android evidence, mobile device compromise, stalkerware detection, malware detection, expert witness, cpr part 35, digital forensic expert, mobile phone forensics, android investigation Android's openness creates a larger threat surface, making sideloaded stalkerware and malware easier to install. This guide details how to detect compromise, the importance of safety, and where evidence lives, helping UK lawyers understand and address Android security issues. ### Android Messaging SMS RCS And Messaging Apps Page: https://e-discovery.uk/library/android-messaging-sms-rcs-and-messaging-apps PDF: https://e-discovery.uk/api/public/library/android-messaging-sms-rcs-and-messaging-apps Category: Guide Published: 2026-09-02 Pages: 19 Topics: Mobile and messaging evidence Keywords: android messaging, sms, rcs, messaging apps, android forensics, deleted messages, message recovery, digital forensics, e-discovery, google account, mobile forensics, text messages, chat apps, android data, electronic evidence, forensic expert Android devices lack a single messaging app, meaning SMS and RCS are handled by various apps, each storing data differently. This guide explains where messages reside, what survives deletion, and the implications for evidence recovery and attribution in legal contexts. ### Android Photos Media And Metadata Page: https://e-discovery.uk/library/android-photos-media-and-metadata PDF: https://e-discovery.uk/api/public/library/android-photos-media-and-metadata Category: Guide Published: 2026-09-02 Pages: 18 Topics: Mobile and messaging evidence, Metadata and timestamps Keywords: android photos, android media, android metadata, android forensics, mobile forensics, digital forensics, android images, google photos, sd card, media store, photo recovery, deleted photos, location data, exif data, metadata analysis, chain of custody, digital evidence, disclosure Android photographs record when, where, and on what they were taken, similar to an iPhone's. This guide explores where these images reside, including the Gallery, Media Store, Google Photos, and SD card, and how to interpret their associated metadata for legal contexts. ### Android Secure Folders Knox And Manufacturer Security Containers Page: https://e-discovery.uk/library/android-secure-folders-knox-and-manufacturer-security-containers PDF: https://e-discovery.uk/api/public/library/android-secure-folders-knox-and-manufacturer-security-containers Category: Guide Published: 2026-09-02 Pages: 19 Topics: Mobile and messaging evidence Keywords: android secure folder, knox container, private space, work profile, mobile forensics, digital evidence, data recovery, e-discovery, disclosure, mobile phone data, hidden data, forensic imaging, device security, android security, evidence preservation, digital forensic expert Many Android phones feature a second, separately locked space, such as Secure Folder, Knox, or work profiles. These containers hold their own apps, messages, photos, and files, sealed behind unique credentials. This guide details how to find and lawfully access these critical evidence locations. ### Android Usage Activity And System Artefacts Page: https://e-discovery.uk/library/android-usage-activity-and-system-artefacts PDF: https://e-discovery.uk/api/public/library/android-usage-activity-and-system-artefacts Category: Guide Published: 2026-09-02 Pages: 19 Topics: Mobile and messaging evidence Keywords: android activity, android usage, mobile forensics, device activity reconstruction, digital forensics, android artefacts, usage stats, digital wellbeing, notifications, phone logs, mobile phone evidence, expert report, cpr part 35, mobile device forensics, android timeline, device timeline Android phones maintain a detailed record of user interaction and system events. This guide explores these usage statistics, digital wellbeing data, notifications, and logs, explaining how they reconstruct device activity timelines and what they can prove in legal contexts. ### Apple Mail Archives And Email Threading On MacOS Page: https://e-discovery.uk/library/apple-mail-archives-and-email-threading-on-macos PDF: https://e-discovery.uk/api/public/library/apple-mail-archives-and-email-threading-on-macos Category: Guide Published: 2026-09-02 Pages: 17 Topics: Processing and review, Email evidence, Apple and macOS forensics Keywords: apple mail threading, email threading, macos email forensics, apple mail archives, email headers, reconstructing email threads, doctored emails, selective disclosure email, email authentication, mac forensics, digital forensics email, email evidence, mac mailboxes, email chain integrity, email preservation mac, uk e-discovery Apple Mail archives and email threading on macOS are crucial for reconstructing email conversations. This guide helps UK lawyers understand where Apple Mail stores data, what headers reveal, and how to authenticate threads, addressing common mistakes and technical limitations. ### Apple Watch And Paired Device Forensics Page: https://e-discovery.uk/library/apple-watch-and-paired-device-forensics PDF: https://e-discovery.uk/api/public/library/apple-watch-and-paired-device-forensics Category: Guide Published: 2026-09-02 Pages: 18 Topics: Apple and macOS forensics Keywords: apple watch forensics, paired device forensics, digital forensics, wearable device forensics, mobile forensics, apple watch data, iphone forensics, attribution, e-discovery, expert evidence, cpr part 35, forensic acquisition, forensic interpretation, digital evidence, watch forensics, apple watch The Apple Watch offers unique forensic data, strengthening attribution and providing evidence independent of a phone. This guide explains its data types, acquisition methods, and how it integrates into a wider digital estate, assisting UK litigators and investigators. ### Gatekeeper XProtect And MacOS Malware Artefacts Page: https://e-discovery.uk/library/gatekeeper-xprotect-and-macos-malware-artefacts PDF: https://e-discovery.uk/api/public/library/gatekeeper-xprotect-and-macos-malware-artefacts Category: Guide Published: 2026-09-02 Pages: 17 Topics: Apple and macOS forensics, Cyber incidents and ransomware Keywords: macos malware, gatekeeper, xprotect, mac forensics, malware defence, virus defence, digital forensics, mac artefacts, computer forensics, mac security, e-discovery, macintosh malware, mac virus, forensic investigation, mac os malware, mac os x malware Macs are susceptible to malware, and Apple's built-in security features, Gatekeeper and XProtect, record activity. These records provide crucial forensic artefacts for investigating genuine compromises and impartially testing the "a virus did it" defence in legal contexts. ### Guide 5 Identifying The Right Custodians In Electronic Disclosure Page: https://e-discovery.uk/library/guide-5-identifying-the-right-custodians-in-electronic-disclosure PDF: https://e-discovery.uk/api/public/library/guide-5-identifying-the-right-custodians-in-electronic-disclosure Category: Guide Published: 2026-09-02 Pages: 32 Topics: Custodians and data mapping, Electronic disclosure practice Keywords: custodians, electronic disclosure, e-disclosure, custodian identification, custodian list, custodian interview, disclosure review document, drd, pd57ad, cpr part 31, legal hold, preservation, shared mailboxes, service accounts, former employees, personal devices, byod, uk gdpr Identifying the right custodians is crucial for electronic disclosure. This guide covers building and prioritising custodian lists, addressing special categories, and navigating legal and practical considerations. It includes a question bank for custodian interviews and model wording for various scenarios. ### ICloud The Account As The Real Evidence Store Page: https://e-discovery.uk/library/icloud-the-account-as-the-real-evidence-store PDF: https://e-discovery.uk/api/public/library/icloud-the-account-as-the-real-evidence-store Category: Guide Published: 2026-09-02 Pages: 19 Topics: Cloud evidence Keywords: icloud evidence, icloud forensics, icloud data collection, digital evidence, cloud forensics, mobile forensics, advanced data protection, adp, apple id, iphone evidence, ipad evidence, e-discovery, e-disclosure, disclosure, computer forensics, electronic evidence iCloud accounts frequently hold critical evidence, including photos, messages, and device backups, even when physical devices are lost or wiped. This guide details what iCloud contains, why it is a primary evidence source, and the lawful methods for accessing this data, including considerations for Advanced Data Protection. ### IMessage SMS And Messaging Apps On IOS Page: https://e-discovery.uk/library/imessage-sms-and-messaging-apps-on-ios PDF: https://e-discovery.uk/api/public/library/imessage-sms-and-messaging-apps-on-ios Category: Guide Published: 2026-09-02 Pages: 17 Topics: Mobile and messaging evidence Keywords: ios messaging forensics, iphone messages, sms recovery, imessage recovery, messaging app data, deleted messages, edited messages, end-to-end encryption, digital forensics, mobile forensics, e-discovery, data recovery, forensic expert, ipad messages, icloud data, attribution Understanding iOS messaging data is crucial for e-discovery. This guide details how iMessage, SMS, and other app conversations are stored, what survives deletion, the impact of edits and encryption, and how to recover and prove these communications. It also covers common mistakes and technical limitations. ### IOS App Data And Third Party Application Forensics Page: https://e-discovery.uk/library/ios-app-data-and-third-party-application-forensics PDF: https://e-discovery.uk/api/public/library/ios-app-data-and-third-party-application-forensics Category: Guide Published: 2026-09-02 Pages: 17 Topics: Deleted data and recovery Keywords: ios app forensics, third party app data, mobile forensics, iphone forensics, app data recovery, digital forensics, mobile phone evidence, ios data, app evidence, forensic expert, e-discovery, disclosure iOS apps are individual worlds of evidence, each storing data uniquely. This guide explores how to recover and interpret this data, addressing common mistakes and technical limitations. It provides guidance on when to involve a digital forensic expert for third-party application forensics. ### IOS Backups ITunes Finder And ICloud Page: https://e-discovery.uk/library/ios-backups-itunes-finder-and-icloud PDF: https://e-discovery.uk/api/public/library/ios-backups-itunes-finder-and-icloud Category: Guide Published: 2026-09-02 Pages: 17 Topics: Cloud evidence Keywords: ios backups, iphone backups, ipad backups, itunes backup, finder backup, icloud backup, mobile forensics, digital forensics, encrypted backup, deleted data recovery, locked phone, electronic evidence, e-discovery, disclosure This guide provides UK legal professionals with an understanding of iOS backups, including iTunes, Finder, and iCloud. It covers their location, content, and the benefits of encryption, offering practical advice for litigation and investigation. ### IOS Encrypted Apps And Secure Messengers Page: https://e-discovery.uk/library/ios-encrypted-apps-and-secure-messengers PDF: https://e-discovery.uk/api/public/library/ios-encrypted-apps-and-secure-messengers Category: Guide Published: 2026-09-02 Pages: 18 Topics: Encryption and access Keywords: secure messenger recovery, encrypted app forensics, ios forensics, signal forensics, telegram forensics, wickr forensics, mobile phone data recovery, digital forensics, electronic disclosure, edisclosure, iphone data, endpoint recovery, icloud data, apfs snapshots, device data Secure messengers like Signal, Telegram, and Wickr protect messages in transit, not necessarily on the device itself. This guide explores what is recoverable from iOS devices, where recovery genuinely stops, and common mistakes in digital forensics. ### IOS Full File System Vs Logical Acquisition Page: https://e-discovery.uk/library/ios-full-file-system-vs-logical-acquisition PDF: https://e-discovery.uk/api/public/library/ios-full-file-system-vs-logical-acquisition Category: Guide Published: 2026-09-02 Pages: 17 Topics: Forensic collection and imaging Keywords: ios acquisition, full file system acquisition, logical acquisition, iphone forensics, ipad forensics, mobile device forensics, digital forensics, data extraction, e-disclosure, e-discovery, cpr part 35, expert report, chain of custody, deleted messages, mobile phone data This guide for UK lawyers explains the critical differences between iOS logical and full-file-system acquisitions. It details what each method reaches and misses, its availability, and how to match the extraction depth to the specific legal matter. Understanding these methods is crucial for effective digital evidence collection. ### IOS Health Fitness And Motion Data Page: https://e-discovery.uk/library/ios-health-fitness-and-motion-data PDF: https://e-discovery.uk/api/public/library/ios-health-fitness-and-motion-data Category: Guide Published: 2026-09-02 Pages: 17 Topics: Cross-border and data protection, Expert evidence and reports Keywords: ios health data, ios motion data, fitness data, special-category data, digital forensics, cpr part 35, expert report, uk gdpr, data protection, iphone evidence, apple watch data, mobile data, e-discovery, steps data, sleep data, movement data, location data, healthkit iOS health, fitness, and motion data serves as a quiet witness, providing insights into activity. This guide for UK lawyers details its recovery, interpretation, and deployment in legal contexts, addressing its special-category status and technical limitations for expert evidence. ### IOS Knowledge And Biome The Device Activity Record Page: https://e-discovery.uk/library/ios-knowledge-and-biome-the-device-activity-record PDF: https://e-discovery.uk/api/public/library/ios-knowledge-and-biome-the-device-activity-record Category: Guide Published: 2026-09-02 Pages: 18 Topics: Expert evidence and reports, Timelines and reconstruction Keywords: ios knowledge c, ios biome, device activity record, iphone activity, mobile forensics, digital forensics, device timeline, cpr part 35 expert, expert report, activity databases, phone activity, mobile device data, digital evidence, e-discovery, disclosure, expert witness, forensic analysis, data reconstruction An iPhone maintains a detailed diary of its use in internal databases, recording app usage, screen state, notifications, and connections. This guide explains how these records can reconstruct user activity, why expert analysis is critical for interpretation, and the limitations involved. ### IOS Location Services Significant And Frequent Locations Page: https://e-discovery.uk/library/ios-location-services-significant-and-frequent-locations PDF: https://e-discovery.uk/api/public/library/ios-location-services-significant-and-frequent-locations Category: Guide Published: 2026-09-02 Pages: 17 Topics: Expert evidence and reports Keywords: ios location services, significant locations, frequent locations, iphone location, mobile phone location, location data, location accuracy, location attribution, cell site data, cell fix, geotags, app location, network location, cpr part 35, digital forensics, forensic expert, location evidence, device location iOS devices store location data in multiple formats, including encrypted Significant Locations, app data, and photo geotags. This guide details how to understand, attribute, and lawfully access this evidence for legal matters, ensuring accuracy and proper deployment in time and place. ### IOS Photos Media And Location Metadata Page: https://e-discovery.uk/library/ios-photos-media-and-location-metadata PDF: https://e-discovery.uk/api/public/library/ios-photos-media-and-location-metadata Category: Guide Published: 2026-09-02 Pages: 17 Topics: Metadata and timestamps Keywords: ios photos metadata, location metadata, digital forensics, mobile forensics, photo metadata, exif data, geotagging, edited photos, deleted photos, altered media, photos library, iphone photos, ipad photos, e-discovery, electronic evidence, disclosure Photographs record more than just images; their metadata and location data offer crucial insights into when and where they were taken. This guide details how to honestly interpret iOS Photos library data, including edited or deleted media, to establish facts in legal and investigative contexts. ### IOS Spyware Stalkerware And Mobile Compromise Page: https://e-discovery.uk/library/ios-spyware-stalkerware-and-mobile-compromise PDF: https://e-discovery.uk/api/public/library/ios-spyware-stalkerware-and-mobile-compromise Category: Guide Published: 2026-09-02 Pages: 19 Topics: Mobile and messaging evidence Keywords: ios spyware, stalkerware, mobile compromise, covert surveillance, iphone forensics, digital forensics, mobile phone tracking, apple device compromise, cpr part 35 expert, duty of care, victim safety, e-discovery, mobile evidence, digital evidence, icloud evidence, forensic analysis This guide for UK lawyers explains how iOS devices can be compromised by spyware, stalkerware, or misused features. It covers detection, the critical duty of care for victim safety, and how to handle mobile evidence in such sensitive cases, including common mistakes and expert involvement. ### IPhone And IPad Forensics The Acquisition Challenge Page: https://e-discovery.uk/library/iphone-and-ipad-forensics-the-acquisition-challenge PDF: https://e-discovery.uk/api/public/library/iphone-and-ipad-forensics-the-acquisition-challenge Category: Guide Published: 2026-09-02 Pages: 17 Topics: Forensic collection and imaging, Mobile and messaging evidence Keywords: iphone forensics, ipad forensics, ios acquisition, mobile device forensics, data extraction challenges, digital evidence seizure, passcode bypass, encrypted devices, remote wipe, chain of custody, cpr part 35 expert report, digital forensic expert, mobile phone forensics, apple device forensics Forensic acquisition of iPhone and iPad devices presents significant challenges due to encryption and security features. This guide for UK lawyers details why iOS resists acquisition, the factors influencing data recovery, and crucial handling at seizure, helping practitioners set realistic expectations and understand technical limitations. ### IPhone Forensics The Defensible Mobile Evidence Bundle Page: https://e-discovery.uk/library/iphone-forensics-the-defensible-mobile-evidence-bundle PDF: https://e-discovery.uk/api/public/library/iphone-forensics-the-defensible-mobile-evidence-bundle Category: Guide Published: 2026-09-02 Pages: 18 Topics: Chain of custody and defensibility, Mobile and messaging evidence Keywords: iphone forensics, mobile evidence bundle, defensible mobile evidence, iphone data, mobile device forensics, digital forensics, mobile phone forensics, iphone backups, icloud forensics, mobile phone data, cpr part 35 expert report, chain of custody, mobile evidence, iphone The guide details how to build a defensible mobile evidence bundle from an iPhone's diverse data sources. It covers the process from seizure to report, addressing convergence, weakest link testing, and deployment, ensuring the bundle withstands challenge in legal proceedings. ### MacOS Enterprise Management And MDM Artefacts Page: https://e-discovery.uk/library/macos-enterprise-management-and-mdm-artefacts PDF: https://e-discovery.uk/api/public/library/macos-enterprise-management-and-mdm-artefacts Category: Guide Published: 2026-09-02 Pages: 19 Topics: Apple and macOS forensics Keywords: macos enterprise management, mdm artefacts, managed mac, mobile device management, digital forensics, ediscovery, locked device, mdm console, mac artefacts, cpr part 35, expert report, chain of custody, macbook, apple device, forensic analysis, enterprise management Workplace Macs are typically managed via MDM, creating digital artefacts. This guide details how managed Macs and MDM function, the evidence they generate, and where it resides. It covers lawful access, common pitfalls, and when to engage a digital forensic expert for UK litigation. ### MacOS Mail Messages And Notes Forensics Page: https://e-discovery.uk/library/macos-mail-messages-and-notes-forensics PDF: https://e-discovery.uk/api/public/library/macos-mail-messages-and-notes-forensics Category: Guide Published: 2026-09-02 Pages: 17 Topics: Apple and macOS forensics Keywords: macos forensics, mac mail forensics, mac messages forensics, mac notes forensics, icloud forensics, deleted data recovery, digital forensics, electronic evidence, communication trail, e-discovery, forensic analysis, data preservation, attribution, expert witness, computer forensics lab The guide explores how Mail, Messages, and Notes data persists on macOS and iCloud, even after deletion. It covers recovery, interpretation, attribution, and deployment of this digital evidence, highlighting common mistakes and when to engage a digital forensic expert for UK litigation. ### MacOS Spotlight And Metadata Deep Dive Page: https://e-discovery.uk/library/macos-spotlight-and-metadata-deep-dive PDF: https://e-discovery.uk/api/public/library/macos-spotlight-and-metadata-deep-dive Category: Guide Published: 2026-09-02 Pages: 17 Topics: Apple and macOS forensics, Metadata and timestamps Keywords: macos spotlight, mac metadata, deleted files mac, mac forensic analysis, mac evidence, spotlight index, file origin mac, mac computer forensics, mac data recovery, mac os x forensics, mac os forensics, mac file provenance, cpr part 35 expert, digital forensics mac, mac os artefacts, mac os artifacts Spotlight indexes Mac files with extensive metadata, including origin and dates. This guide details how these index entries can prove a file's past existence and provenance, even after deletion, offering crucial insights for UK litigators and investigators. ### Safari And Browser Artefacts On MacOS Page: https://e-discovery.uk/library/safari-and-browser-artefacts-on-macos PDF: https://e-discovery.uk/api/public/library/safari-and-browser-artefacts-on-macos Category: Guide Published: 2026-09-02 Pages: 17 Topics: Apple and macOS forensics Keywords: macos browser artefacts, safari forensics, browser history recovery, icloud sync forensics, mac web activity, digital forensics macos, browser data analysis, cleared browser data, web browsing evidence, cpr part 35 expert, third party browsers, computer forensics, mac artefacts, safari history, web activity, mac forensics Safari and other browsers on macOS record web activity in local artefacts, often synced via iCloud. This guide explains where this evidence lives, how it can be recovered even after clearing, and its use in proving web activity and intent for UK litigation. ### The Google Account Androids Cloud Estate Page: https://e-discovery.uk/library/the-google-account-androids-cloud-estate PDF: https://e-discovery.uk/api/public/library/the-google-account-androids-cloud-estate Category: Guide Published: 2026-09-02 Pages: 18 Topics: Mobile and messaging evidence, Cloud evidence Keywords: google account, android forensics, mobile forensics, location history, digital evidence, cloud forensics, e-discovery, disclosure, computer forensics, data retention, lawful access, digital forensic expert, mobile phone data, device backups, activity records, cpr part 35, crimpr part 19, chain of custody Behind nearly every Android phone, a Google account stores backups, photos, messages, files, and distinctive activity records. This guide explores what the account holds, how to access it lawfully, user controls, and its deployment as a primary or fallback evidence source for UK legal professionals. ### Time Machine And MacOS Backup Analysis Page: https://e-discovery.uk/library/time-machine-and-macos-backup-analysis PDF: https://e-discovery.uk/api/public/library/time-machine-and-macos-backup-analysis Category: Guide Published: 2026-09-02 Pages: 17 Topics: Apple and macOS forensics Keywords: macos backup analysis, time machine analysis, mac forensics, deleted files mac, prior state analysis, version analysis, mac evidence recovery, apple backup forensics, digital forensics mac, cpr part 35 expert report, mac os x backup, icloud backup, apfs snapshots, mac system logs, mac authentication, mac data recovery Time Machine creates regular, versioned backups of a Mac, acting as a second machine that remembers what the first one deleted. This guide explores how these backups work, what they preserve, and how they can be used to recover prior states and deleted data for legal and investigative purposes. ### Wear OS And Android Paired Device Forensics Page: https://e-discovery.uk/library/wear-os-and-android-paired-device-forensics PDF: https://e-discovery.uk/api/public/library/wear-os-and-android-paired-device-forensics Category: Guide Published: 2026-09-02 Pages: 19 Topics: Mobile and messaging evidence Keywords: wear os forensics, android paired device forensics, smartwatch forensics, wearable device forensics, android tablet forensics, earbuds forensics, in-car system forensics, digital forensics, e-discovery, mobile device forensics, attribution evidence, cpr part 35 expert report, chain of custody, digital evidence, forensic expert Android phones are often connected to smartwatches, tablets, earbuds, and cars, forming a wider digital estate. This guide explores what these paired devices record, how they strengthen attribution, and their potential to provide evidence even if a phone is wiped or lost. It covers acquisition, interpretation, and common technical limitations. ### CFL Benefits Of Early Case Assessment In EDiscovery Page: https://e-discovery.uk/library/cfl-benefits-of-early-case-assessment-in-ediscovery PDF: https://e-discovery.uk/api/public/library/cfl-benefits-of-early-case-assessment-in-ediscovery Category: Guide Published: 2026-09-01 Pages: 45 Topics: Costs and early case assessment, Electronic disclosure practice Keywords: early case assessment, eca, ediscovery, disclosure, disclosure costs, case strategy, electronically stored information, esi, pd 57ad, cpr part 31, early data assessment, eda, uk data protection, privilege, microsoft 365 Early Case Assessment (ECA) is the early analysis of a dispute's facts, legal issues, and evidence, alongside Early Data Assessment (EDA) of electronically stored information. This guide explains how ECA provides knowledge to inform strategy, scope, budget, and preservation decisions, moving legal teams from assumptions to measurable data. ### AI Generated Documents Provenance And Detection Page: https://e-discovery.uk/library/ai-generated-documents-provenance-and-detection PDF: https://e-discovery.uk/api/public/library/ai-generated-documents-provenance-and-detection Category: Guide Published: 2026-08-31 Pages: 17 Topics: AI and synthetic media Keywords: ai generated documents, document provenance, ai detection, fabricated evidence, hallucinated citations, ai documents, digital forensics, metadata analysis, ai content detection, forensic examination, ai text detection, document authenticity, ai generated text, native files, e-discovery, computer forensics AI can generate plausible documents rapidly, but text analysis for detection is weak. This guide explains how provenance, examining a document's origin and history, provides the forensic solution for UK legal professionals. ### APFS And The Apple File System Page: https://e-discovery.uk/library/apfs-and-the-apple-file-system PDF: https://e-discovery.uk/api/public/library/apfs-and-the-apple-file-system Category: Guide Published: 2026-08-31 Pages: 17 Topics: Apple and macOS forensics Keywords: apfs, apple file system, apple devices, deleted data recovery, digital forensics, snapshots, clones, copy on write, iphone forensics, ipad forensics, mac forensics, expert reports, cpr part 35, data recovery, electronic evidence, forensic analysis, timestamps, containers APFS, used on Macs, iPhones, and iPads, preserves deleted and prior data states more often than expected. This guide details how copy-on-write, snapshots, and clones work, where evidence resides, and how to recover and interpret this information for legal proceedings, highlighting common mistakes and technical limits. ### BitLocker FileVault And Full Disk Encryption Page: https://e-discovery.uk/library/bitlocker-filevault-and-full-disk-encryption PDF: https://e-discovery.uk/api/public/library/bitlocker-filevault-and-full-disk-encryption Category: Guide Published: 2026-08-31 Pages: 17 Topics: Apple and macOS forensics, Encryption and access Keywords: full disk encryption, bitlocker, filevault, recovery key, encrypted drive, decryption, digital forensics, ediscovery, luks, cpr part 35, imaging, disclosure, inaccessible drive, expert report, forensic examination, escrow Full disk encryption, such as BitLocker and FileVault, is often recoverable, particularly in managed environments where recovery keys are typically escrowed. This guide details how these systems work, where keys reside, and how to lawfully obtain and image decrypted volumes for litigation or investigation. It also addresses scenarios where keys are genuinely absent. ### Browser History And Internet Artefacts Page: https://e-discovery.uk/library/browser-history-and-internet-artefacts PDF: https://e-discovery.uk/api/public/library/browser-history-and-internet-artefacts Category: Guide Published: 2026-08-31 Pages: 17 Topics: Open source, web and log evidence Keywords: browser history, internet artefacts, digital forensics, computer forensics, ediscovery, web browser evidence, internet activity, browser data, digital evidence, forensic examination, cpr part 35, expert reports, deleted history recovery, incognito browsing, private browsing, web searches, downloads, cookies Browser history and internet artefacts record visits, searches, and downloads. This guide for UK lawyers details what browsers record, how to interpret these artefacts, and the limits of their evidential value, including distinguishing deliberate actions from automatic activity. ### Can File Timestamps Be Trusted Page: https://e-discovery.uk/library/can-file-timestamps-be-trusted PDF: https://e-discovery.uk/api/public/library/can-file-timestamps-be-trusted Category: Guide Published: 2026-08-31 Pages: 17 Topics: Metadata and timestamps Keywords: file timestamps, timestamp reliability, digital forensics, electronic evidence, timestamp manipulation, computer forensics, ediscovery, metadata, date and time evidence, forensic analysis, cpr part 35, expert reports, chain of custody, digital evidence, electronic documents File timestamps are records, not facts. This guide details the different timestamp families, common causes of innocent rewrites, and how manipulation leaves traces. It covers trustworthiness in practice, common mistakes, and when to involve a digital forensic expert. ### Can You Prove Who Deleted A File Page: https://e-discovery.uk/library/can-you-prove-who-deleted-a-file PDF: https://e-discovery.uk/api/public/library/can-you-prove-who-deleted-a-file Category: Guide Published: 2026-08-31 Pages: 17 Topics: Deleted data and recovery Keywords: file deletion attribution, who deleted a file, digital forensics deletion, deletion artefacts, audit trails, computer forensics, spoliation of evidence, ediscovery deletion, cpr part 35 expert reports, cloud deletion, server deletion, local deletion, recycle bin forensics, file system journal analysis, wiping tools forensics, anti-forensics, metadata residue, expert witness digital forensics Deletion is an act with actors, and platforms record it. This guide explores how to attribute file deletion to an account or person, covering cloud, server, and local deletion, deliberate erasure, and the wider evidence architecture. It details common mistakes, technical limitations, and when to involve a digital forensic expert. ### Collecting Evidence From Microsoft Teams Private And Shared Channels Page: https://e-discovery.uk/library/collecting-evidence-from-microsoft-teams-private-and-shared-channels PDF: https://e-discovery.uk/api/public/library/collecting-evidence-from-microsoft-teams-private-and-shared-channels Category: Guide Published: 2026-08-31 Pages: 17 Topics: Forensic collection and imaging, Slack and Teams Keywords: microsoft teams evidence, teams private channel, teams shared channel, teams collection, teams ediscovery, teams data location, teams disclosure, microsoft 365 evidence, sharepoint, exchange online, disclosure review document, drd, cpr part 31, pd 57ad, forensic collection, digital forensics Collecting evidence from Microsoft Teams private and shared channels requires understanding where data lives, as a collection scoped to the team may miss them. This guide details storage locations, lifecycle, holds, and reconstruction for UK litigators. ### Collecting Without The Password Page: https://e-discovery.uk/library/collecting-without-the-password PDF: https://e-discovery.uk/api/public/library/collecting-without-the-password Category: Guide Published: 2026-08-31 Pages: 18 Topics: Forensic collection and imaging, Encryption and access Keywords: locked device access, withheld password, compelled access, digital forensics, disclosure orders, unless orders, statutory notice regime, cpr part 35, mobile handset, encrypted data, cloud recovery, server-side compulsion, corporate device, digital evidence, password recovery, data access When evidence is locked away by encryption or withheld credentials, legal and technical strategies are required. This guide explores civil and criminal routes for compelled access, technical limitations, and alternative methods to secure crucial digital evidence. It also covers common mistakes and expert involvement. ### Cryptocurrency And Blockchain Tracing Page: https://e-discovery.uk/library/cryptocurrency-and-blockchain-tracing PDF: https://e-discovery.uk/api/public/library/cryptocurrency-and-blockchain-tracing Category: Guide Published: 2026-08-31 Pages: 17 Topics: Cryptocurrency and blockchain Keywords: cryptocurrency tracing, blockchain tracing, crypto attribution, digital asset tracing, freezing crypto assets, recovering crypto assets, crypto disclosure, cpr part 35 expert reports, wallet forensics, exchange forensics, public ledger tracing, kyc, seed phrase, crypto mixers, obfuscation Cryptocurrency tracing involves following transactions on public ledgers and attributing addresses to individuals. This guide covers the process from tracing funds across the ledger to identifying owners, addressing obfuscation, and detailing deployment strategies for freezing and recovery. It also includes common mistakes and expert advice. ### Custodian Abroad Cross Border Collection Page: https://e-discovery.uk/library/custodian-abroad-cross-border-collection PDF: https://e-discovery.uk/api/public/library/custodian-abroad-cross-border-collection Category: Guide Published: 2026-08-31 Pages: 17 Topics: Forensic collection and imaging, Cross-border and data protection, Custodians and data mapping Keywords: cross-border collection, custodian abroad, international data transfer, blocking statutes, uk gdpr, foreign law disclosure, cpr part 35 expert reports, data collection abroad, ediscovery cross-border, disclosure duties foreign law, letters of request, in-country collection, cloud-side collection, digital forensic expert, data transfer restrictions, legal hold abroad, evidence abroad, data localisation laws When evidence is located abroad, its collection becomes a complex legal exercise before a technical one. This guide addresses international data transfer, blocking statutes, and local law, outlining routes for collection and the importance of planning with local counsel to reconcile English disclosure duties with foreign law. ### Damaged Computers And Data Recovery Page: https://e-discovery.uk/library/damaged-computers-and-data-recovery PDF: https://e-discovery.uk/api/public/library/damaged-computers-and-data-recovery Category: Guide Published: 2026-08-31 Pages: 17 Topics: Deleted data and recovery Keywords: damaged devices, data recovery, digital forensics, damaged computers, damaged media, broken devices, spoliation, evidence destruction, chip-off, board repair, cpr part 35, expert reports, chain of custody, laptops, phones, hard drives, mobile devices, forensic expert Physically broken devices rarely mean empty ones. Much data survives damage and can be recovered using techniques from board repair to chip-level extraction. The pattern and timing of damage often indicate whether it was accidental or a deliberate attempt to destroy evidence, providing crucial insights for UK litigators and investigators. ### Data Exfiltration To Cloud Storage Page: https://e-discovery.uk/library/data-exfiltration-to-cloud-storage PDF: https://e-discovery.uk/api/public/library/data-exfiltration-to-cloud-storage Category: Guide Published: 2026-08-31 Pages: 17 Topics: Cloud evidence, Data theft and exfiltration Keywords: data exfiltration, cloud exfiltration, data theft, insider threat, employee misconduct, cloud storage, personal cloud, sync clients, browser uploads, sharing events, audit logs, digital forensics, computer forensics, egress analysis, expert reports, cpr part 35, data loss prevention, casb This guide assists UK lawyers in understanding data exfiltration to cloud storage. It covers tracing company data uploaded to personal and third-party clouds, examining the routes, records, and destinations of such transfers, and how to quantify and prove them. ### Deepfakes And Synthetic Media Page: https://e-discovery.uk/library/deepfakes-and-synthetic-media PDF: https://e-discovery.uk/api/public/library/deepfakes-and-synthetic-media Category: Guide Published: 2026-08-31 Pages: 17 Topics: AI and synthetic media Keywords: deepfake, synthetic media, fake video, cloned voice, audio authentication, video authentication, digital forensics, evidence authenticity, provenance, liar s dividend, burden of proof, expert report, cpr part 35, e-discovery, ai generated content, media manipulation, original file, chain of custody AI-generated synthetic media, including deepfakes, challenges traditional notions of authenticity. This guide addresses the creation, detection, and authentication of such media, outlining common pitfalls and the role of digital forensic experts in UK litigation. ### Detecting Backdated Or Manipulated Documents Page: https://e-discovery.uk/library/detecting-backdated-or-manipulated-documents PDF: https://e-discovery.uk/api/public/library/detecting-backdated-or-manipulated-documents Category: Guide Published: 2026-08-31 Pages: 17 Topics: Metadata and timestamps Keywords: document authenticity, backdated documents, manipulated documents, document alteration, digital forensics, metadata analysis, expert reports, cpr part 35, electronic evidence, forgery detection, anachronisms, email forensics, pdf forensics, office document forensics, scanned document analysis, chain of custody, red flags, forensic examination Detecting backdated or manipulated documents involves forensic examination of internal evidence, such as metadata and anachronisms, and external corroboration from the document's expected environment. This guide details methods for identifying alterations and provides insights into grading findings and common pitfalls. ### Digital Forensics In Corporate Fraud Investigations Page: https://e-discovery.uk/library/digital-forensics-in-corporate-fraud-investigations PDF: https://e-discovery.uk/api/public/library/digital-forensics-in-corporate-fraud-investigations Category: Guide Published: 2026-08-31 Pages: 17 Topics: Fraud and corporate investigations Keywords: corporate fraud investigations, digital forensics, financial systems forensics, document authenticity, fraud evidence, covert preservation, cpr part 35 expert reports, accounting data, erp systems, metadata, backdating, fabrication, document alteration, civil fraud, criminal fraud, regulatory fraud, freezing order evidence, expert witness Corporate fraud investigations succeed by forensically linking financial systems data, document metadata, and digital communications. This guide details how to preserve evidence covertly, expose fabrication, and deploy findings in civil, criminal, or regulatory contexts, addressing common mistakes and technical limitations. ### File Wiping Anti Forensics And The Evidence They Leave Behind Page: https://e-discovery.uk/library/file-wiping-anti-forensics-and-the-evidence-they-leave-behind PDF: https://e-discovery.uk/api/public/library/file-wiping-anti-forensics-and-the-evidence-they-leave-behind Category: Guide Published: 2026-08-31 Pages: 17 Topics: Deleted data and recovery Keywords: anti-forensics, file wiping, evidence destruction, data destruction, digital forensics, forensic examination, spoliation, factory reset, data recovery, mobile anti-forensics, cloud anti-forensics, encryption, data obfuscation, digital evidence, litigation hold, disclosure, red flags, expert witness Anti-forensics actions, such as file wiping or device resets, are acts that leave behind examinable traces. This guide details the techniques, the evidence they create, and what survives, helping practitioners understand the consequences of deliberate data destruction. ### FileVault The Secure Enclave And Apple Encryption Page: https://e-discovery.uk/library/filevault-the-secure-enclave-and-apple-encryption PDF: https://e-discovery.uk/api/public/library/filevault-the-secure-enclave-and-apple-encryption Category: Guide Published: 2026-08-31 Pages: 17 Topics: Apple and macOS forensics, Encryption and access Keywords: apple encryption, filevault, secure enclave, recovery key, locked device, decryption, iphone, ipad, icloud, digital forensics, expert report, cpr part 35, lawful access, escrowed key, apple security Apple's encryption, using FileVault and the Secure Enclave, ties device data to both the hardware and the user. This guide explains how this system works, where recovery keys are stored, and the lawful methods for accessing encrypted data on macOS devices. ### Forensic Evidence From Cloud Infrastructure AWS Azure Google Cloud Page: https://e-discovery.uk/library/forensic-evidence-from-cloud-infrastructure-aws-azure-google-cloud PDF: https://e-discovery.uk/api/public/library/forensic-evidence-from-cloud-infrastructure-aws-azure-google-cloud Category: Guide Published: 2026-08-31 Pages: 17 Topics: Cloud evidence Keywords: cloud forensics, cloud infrastructure, aws forensics, azure forensics, google cloud forensics, digital forensics, ediscovery, forensic evidence, control plane logs, data plane logs, cloud storage, cloud compute, data preservation, data collection, ephemeral evidence, cloud security breaches, forensic expert, cloud investigations Forensic evidence from cloud infrastructure, such as AWS, Azure, and Google Cloud, resides in the account, not the server. This guide details how control-plane and data-plane logs record actions and data events, and how these are preserved through provider mechanisms. ### Forensic Evidence From Dropbox Box And ShareFile Page: https://e-discovery.uk/library/forensic-evidence-from-dropbox-box-and-sharefile PDF: https://e-discovery.uk/api/public/library/forensic-evidence-from-dropbox-box-and-sharefile Category: Guide Published: 2026-08-31 Pages: 17 Topics: Cloud evidence Keywords: dropbox forensic evidence, box forensic evidence, sharefile forensic evidence, file sharing platform forensics, digital forensics, ediscovery, activity logs, sharing trails, sync artefacts, desktop client forensics, data exfiltration, disclosure, expert reports, cpr part 35, computer forensics, forensic collection This guide details how to uncover forensic evidence from independent file platforms such as Dropbox, Box, and ShareFile. It covers platform records, desktop client artefacts, and external collaboration trails. Learn about preservation, collection, and deployment strategies for cloud evidence, including common mistakes and expert involvement. ### Geolocation Evidence Page: https://e-discovery.uk/library/geolocation-evidence PDF: https://e-discovery.uk/api/public/library/geolocation-evidence Category: Guide Published: 2026-08-31 Pages: 17 Topics: Open source, web and log evidence Keywords: geolocation evidence, location data, digital forensics, expert reports, cpr part 35, gps, wi-fi location, cell site analysis, exif data, app data, cloud location history, location accuracy, alibi evidence, movement analysis, timeline correlation Geolocation evidence comes from diverse sources like GPS, Wi-Fi, cell, EXIF, and app data. This guide addresses their different reliability, how to correlate them onto a timeline, and the importance of honest confidence in presenting findings. It covers common mistakes, technical limitations, and when to involve a digital forensic expert. ### How Lawyers Should Instruct A Digital Forensic Expert Page: https://e-discovery.uk/library/how-lawyers-should-instruct-a-digital-forensic-expert PDF: https://e-discovery.uk/api/public/library/how-lawyers-should-instruct-a-digital-forensic-expert Category: Guide Published: 2026-08-31 Pages: 17 Topics: Expert evidence and reports Keywords: instructing digital forensic expert, digital forensics instruction, expert witness instruction, forensic science regulator s code, fsr code, cpr 35, crimpr 19, expert report, single joint expert, sje, digital evidence, computer forensics, electronic evidence, expert independence, instruction letter, expert selection, digital forensic expert This guide details how UK lawyers should instruct digital forensic experts, covering expert selection, instruction drafting, compliance with the Forensic Science Regulator's Code, and report requirements under CPR 35 and CrimPR 19. It also addresses managing the engagement and common pitfalls. ### MacOS And Apple Silicon Forensics Page: https://e-discovery.uk/library/macos-and-apple-silicon-forensics PDF: https://e-discovery.uk/api/public/library/macos-and-apple-silicon-forensics Category: Guide Published: 2026-08-31 Pages: 17 Topics: Apple and macOS forensics Keywords: macos forensics, apple silicon forensics, mac acquisition, live acquisition, mac evidence, apple forensics, mac imaging, secure boot, hardware encryption, icloud evidence, mac data preservation, digital forensics mac, apple m1 forensics, apple m2 forensics, macintosh forensics, mac data recovery Modern Macs present unique challenges for forensic acquisition due to hardware encryption and secure boot. This guide details why traditional imaging fails, how live logical acquisition is performed, and the importance of credentials and cooperation. It also covers common mistakes, technical limitations, and where else evidence may reside. ### MacOS System Artefacts Page: https://e-discovery.uk/library/macos-system-artefacts PDF: https://e-discovery.uk/api/public/library/macos-system-artefacts Category: Guide Published: 2026-08-31 Pages: 17 Topics: Apple and macOS forensics Keywords: macos forensics, mac forensics, mac system artefacts, macos activity timeline, mac activity reconstruction, unified logs, activity databases, spotlight artefacts, fsevents, knowledgec, mac digital evidence, mac e-discovery, cpr part 35 expert reports, mac expert witness, mac data recovery macOS system artefacts provide a detailed record of user activity, answering who-did-what-when questions in disputes. This guide covers principal artefacts, activity timeline reconstruction, interpretation, and common limitations for UK legal professionals. ### OSINT Open Source Intelligence In Litigation Page: https://e-discovery.uk/library/osint-open-source-intelligence-in-litigation PDF: https://e-discovery.uk/api/public/library/osint-open-source-intelligence-in-litigation Category: Guide Published: 2026-08-31 Pages: 17 Topics: Open source, web and log evidence Keywords: osint, open source intelligence, litigation, digital evidence, evidence authentication, evidence preservation, asset tracing, due diligence, fact testing, social media evidence, web evidence, public data, digital forensics, legal limits, ethical limits, verification, corroboration, attribution Open source intelligence (OSINT) involves gathering public data for litigation. This guide covers capturing, preserving, verifying, and attributing OSINT to ensure it is lawful and proportionate. It details the open sources, legal limits, deployment, and common mistakes, helping practitioners turn information into admissible evidence. ### Preserving Evidence After A Cyber Attack Or Ransomware Incident Page: https://e-discovery.uk/library/preserving-evidence-after-a-cyber-attack-or-ransomware-incident PDF: https://e-discovery.uk/api/public/library/preserving-evidence-after-a-cyber-attack-or-ransomware-incident Category: Guide Published: 2026-08-31 Pages: 17 Topics: Preservation and legal holds, Cyber incidents and ransomware Keywords: cyber attack evidence preservation, ransomware incident evidence, digital forensics cyber attack, incident response evidence, cyber incident preservation, evidence recovery cyber, computer forensics lab, intrusion timeline reconstruction, cpr part 35 expert reports, chain of custody, ico, regulators, insurers cyber, ir firms, volatile data, server logs, endpoint security, network security Understanding how to preserve evidence after a cyber attack or ransomware incident is crucial for UK litigators, in-house counsel, and investigators. This guide details the necessary steps to secure digital evidence, supporting legal and regulatory obligations while navigating business recovery challenges. ### Proving Who Created Or Edited A Document Page: https://e-discovery.uk/library/proving-who-created-or-edited-a-document PDF: https://e-discovery.uk/api/public/library/proving-who-created-or-edited-a-document Category: Guide Published: 2026-08-31 Pages: 17 Topics: Metadata and timestamps Keywords: document authorship, authorship attribution, document creation, document editing, digital forensics, metadata, version ladders, audit logs, platform evidence, endpoint evidence, transmission evidence, content analysis, linguistic analysis, stylistic analysis, ediscovery, computer forensics Attributing authorship or edits to a document requires a forensic approach, combining internal metadata, platform evidence, endpoint records, and content analysis. This guide details how to build a robust case, addressing common pitfalls and technical limitations for UK litigators, in-house counsel, and investigators. ### RAID NAS And Server Recovery Page: https://e-discovery.uk/library/raid-nas-and-server-recovery PDF: https://e-discovery.uk/api/public/library/raid-nas-and-server-recovery Category: Guide Published: 2026-08-31 Pages: 18 Topics: Servers, NAS and virtual environments, Deleted data and recovery Keywords: raid recovery, nas recovery, server recovery, digital forensics, e-discovery, array reconstruction, failed array, degraded array, forensic imaging, data preservation, disclosure, spoliation, expert report, cpr part 35, chain of custody, electronic evidence, live server preservation, raid array This guide for UK lawyers addresses the complexities of recovering data from RAID arrays, Network Attached Storage, and servers. It covers reconstruction methods, handling failed systems, preserving live storage, and avoiding common pitfalls to ensure evidence integrity. ### Recovering Deleted CCTV And DVR Footage Page: https://e-discovery.uk/library/recovering-deleted-cctv-and-dvr-footage PDF: https://e-discovery.uk/api/public/library/recovering-deleted-cctv-and-dvr-footage Category: Guide Published: 2026-08-31 Pages: 17 Topics: Deleted data and recovery, CCTV and physical access evidence Keywords: cctv recovery, dvr recovery, deleted cctv footage, overwritten cctv footage, cctv preservation, dvr preservation, video forensics, digital video recorder, network video recorder, cctv evidence, dvr evidence, cpr part 35 expert reports, chain of custody, video authenticity, video timestamps, cctv disclosure, video retention, forensic video analysis CCTV and DVR systems automatically overwrite footage, creating an urgent need for preservation. This guide details how these systems store and delete data, the critical first steps for preservation, and methods for recovering deleted or overwritten footage, including considerations for authenticity and deployment in legal cases. ### Recovering Evidence From Deleted Microsoft 365 User Accounts Page: https://e-discovery.uk/library/recovering-evidence-from-deleted-microsoft-365-user-accounts PDF: https://e-discovery.uk/api/public/library/recovering-evidence-from-deleted-microsoft-365-user-accounts Category: Guide Published: 2026-08-31 Pages: 17 Topics: Microsoft 365 evidence, Deleted data and recovery Keywords: microsoft 365 deleted accounts, m365 deleted accounts, leaver data recovery, deleted user evidence, inactive mailbox, soft deletion, hard deletion, onedrive recovery, teams data recovery, audit logs, preservation duties, uk gdpr leavers, cpr part 31, forensic expert Microsoft 365 user accounts pass through recoverable states with clocks attached after deletion. Understanding soft deletion, inactive mailboxes, and hard deletion is crucial for evidence recovery. This guide outlines preservation and collection strategies, including reconstruction from the wider estate when an account is gone, and addresses legal consequences of leaver processes. ### Recovering Previous Versions Of Cloud Documents Page: https://e-discovery.uk/library/recovering-previous-versions-of-cloud-documents PDF: https://e-discovery.uk/api/public/library/recovering-previous-versions-of-cloud-documents Category: Guide Published: 2026-08-31 Pages: 17 Topics: Cloud evidence, Deleted data and recovery Keywords: cloud document versions, version history, drafting history, sharepoint versions, onedrive versions, google drive versions, dms versions, document management system versions, version control, digital forensics, edisclosure, disclosure, cpr part 31, authenticity, metadata, audit logs, forensic collection Cloud platforms automatically retain document version histories, complete with attribution and timestamps. This guide details how these versions are kept, what can destroy them, and how to forensically preserve, collect, and interpret this crucial drafting record for litigation and investigations. ### Remote Employee Collection Page: https://e-discovery.uk/library/remote-employee-collection PDF: https://e-discovery.uk/api/public/library/remote-employee-collection Category: Guide Published: 2026-08-31 Pages: 17 Topics: Forensic collection and imaging, Employment and departing employees Keywords: remote collection, remote employee collection, ediscovery, digital forensics, custodian data collection, evidence collection, remote device, personal device collection, byod, chain of custody, data preservation, cpr part 35, uk gdpr, data protection, privacy, self-collection, cloud collection, forensic imaging Remote employee collection is now the ordinary case for e-discovery. This guide details methods like supervised self-collection and shipped media, emphasizing defensibility through documentation, verification, and data minimisation. It addresses cooperation, control, data protection, and common pitfalls for UK litigators. ### SaaS Platforms As Undiscovered Repositories Page: https://e-discovery.uk/library/saas-platforms-as-undiscovered-repositories PDF: https://e-discovery.uk/api/public/library/saas-platforms-as-undiscovered-repositories Category: Guide Published: 2026-08-31 Pages: 17 Topics: Cloud evidence, Custodians and data mapping Keywords: saas discovery, saas platforms, business records, disclosure, e-discovery, digital forensics, audit trails, crm, project management tools, hr systems, messaging platforms, data preservation, data collection, proportionality, cpr part 31 Business records increasingly live inside SaaS applications, not just email and drives. This guide helps UK lawyers map the SaaS estate, preserve platforms against their own retention, and collect structured records and audit trails for disclosure. ### Shared Mailboxes Delegated Access And Who Really Sent The Email Page: https://e-discovery.uk/library/shared-mailboxes-delegated-access-and-who-really-sent-the-email PDF: https://e-discovery.uk/api/public/library/shared-mailboxes-delegated-access-and-who-really-sent-the-email Category: Guide Published: 2026-08-31 Pages: 17 Topics: Email evidence Keywords: shared mailboxes, delegated access, email attribution, who sent email, sender identification, email forensics, send-as, send-on-behalf, email rules, email forwarding, audit logs, mailbox collection, disclosure, ediscovery, digital forensics, email evidence Shared mailboxes and delegated access complicate email attribution, as the 'From' line is a label, not a signature. This guide details access models, collection strategies, and attribution methods using logs, permissions, and devices to prove who acted, not just which mailbox sent the email. ### The Defensible Multi Source Evidence Bundle Page: https://e-discovery.uk/library/the-defensible-multi-source-evidence-bundle PDF: https://e-discovery.uk/api/public/library/the-defensible-multi-source-evidence-bundle Category: Guide Published: 2026-08-31 Pages: 17 Topics: Chain of custody and defensibility Keywords: multi-source evidence bundle, digital evidence assembly, evidence convergence, admissible digital evidence, digital forensics expert, master timeline, chain of custody, cpr part 35 expert reports, devices cloud network media open sources, evidence integrity provenance, contradictory evidence, expert witness instruction, ediscovery, digital evidence presentation This guide explains how to assemble a defensible multi-source evidence bundle for UK litigation. It covers converging evidence from devices, cloud, network, media, and open sources, resolving contradictions, and maintaining integrity to present a coherent, admissible case. ### Vehicle Infotainment And Telematics Forensics Page: https://e-discovery.uk/library/vehicle-infotainment-and-telematics-forensics PDF: https://e-discovery.uk/api/public/library/vehicle-infotainment-and-telematics-forensics Category: Guide Published: 2026-08-31 Pages: 17 Topics: Vehicles, wearables and IoT Keywords: vehicle forensics, infotainment, telematics, connected car data, car data, vehicle data extraction, vehicle data preservation, digital forensics, paired phones, journey data, collision data, expert reports, cpr part 35, uk ediscovery Vehicle infotainment and telematics forensics examines data from modern cars, which record connected phones, journeys, and events. This guide assists UK litigators, in-house counsel, and investigators in understanding how to preserve, extract, and interpret this digital evidence for legal proceedings. ### Wearables And Fitness Tracker Forensics Page: https://e-discovery.uk/library/wearables-and-fitness-tracker-forensics PDF: https://e-discovery.uk/api/public/library/wearables-and-fitness-tracker-forensics Category: Guide Published: 2026-08-31 Pages: 17 Topics: Vehicles, wearables and IoT Keywords: wearable data, fitness tracker forensics, wearable device forensics, digital forensics, health data, gps data, heart rate data, sleep data, activity data, data extraction, data preservation, expert reports, cpr part 35, disclosure, electronic evidence, forensic examination, data accuracy, chain of custody Wearable devices record a body's activity, creating a digital diary of movement, health, and location. This guide explains how to understand, preserve, extract, and deploy this data as evidence, addressing its accuracy, attribution, and limitations for UK legal professionals. ### Who Accessed Or Downloaded A Confidential Document Page: https://e-discovery.uk/library/who-accessed-or-downloaded-a-confidential-document PDF: https://e-discovery.uk/api/public/library/who-accessed-or-downloaded-a-confidential-document Category: Guide Published: 2026-08-31 Pages: 17 Topics: Data theft and exfiltration Keywords: document access, confidential document access, who accessed document, access logs, digital forensics, ediscovery, file access evidence, cloud platforms, sharepoint, onedrive, google drive, file servers, endpoints, data access attribution, log analysis, data retention, disclosure Understanding who accessed or downloaded a confidential document involves examining access trails across cloud platforms, file servers, and endpoints. This guide details what each record proves, retention policies, attribution methods, and common pitfalls for UK legal professionals. ### A Privileged Document Has Been Disclosed What Happens Next Page: https://e-discovery.uk/library/a-privileged-document-has-been-disclosed-what-happens-next PDF: https://e-discovery.uk/api/public/library/a-privileged-document-has-been-disclosed-what-happens-next Category: Guide Published: 2026-08-30 Pages: 17 Topics: Privilege Keywords: inadvertent disclosure, privileged document, privilege waiver, cpr 31.20, clawback, ediscovery, digital forensics, disclosure mistake, document recovery, legal privilege, forensic deletion, containment, expert reports, chain of custody, disclosure protocol, obvious mistake When a privileged document is inadvertently disclosed, speed and evidence are critical. This guide outlines the legal framework, including CPR 31.20, and provides playbooks for both the disclosing and receiving parties, covering immediate actions, evidence gathering, and the technical aspects of recovery. ### Building A Digital Timeline For Litigation Page: https://e-discovery.uk/library/building-a-digital-timeline-for-litigation PDF: https://e-discovery.uk/api/public/library/building-a-digital-timeline-for-litigation Category: Guide Published: 2026-08-30 Pages: 17 Topics: Timelines and reconstruction Keywords: digital timeline, litigation timeline, chronology, digital forensics, e-discovery timeline, timestamp normalisation, event sources, computer forensics, electronic evidence, timeline construction, digital evidence, forensic timeline, data chronology, utc normalisation, clock drift, timeline expert Building a digital timeline for litigation requires careful construction from independent sources, normalisation, and corroboration. This guide details the process, from raw material to defensible presentation, ensuring the chronology serves as evidence rather than mere argument. ### BYOD And Disclosure Page: https://e-discovery.uk/library/byod-and-disclosure PDF: https://e-discovery.uk/api/public/library/byod-and-disclosure Category: Guide Published: 2026-08-30 Pages: 17 Topics: Mobile and messaging evidence Keywords: byod disclosure, bring your own device, personal device data, employee data collection, disclosure obligations, cpr part 31, uk gdpr, data privacy, proportionality, targeted collection, digital forensics, mobile phone data, whatsapp disclosure, custodian consent protocol, wiped devices, expert reports, e-discovery, electronic disclosure This guide for UK lawyers explains how to handle work data on personal devices, covering control, collection routes, and privacy. It details targeted collection protocols, addresses common issues like leavers and wiped devices, and provides practical advice for managing BYOD disclosure. ### Can We Collect Only Relevant Data Instead Of Imaging Everything Page: https://e-discovery.uk/library/can-we-collect-only-relevant-data-instead-of-imaging-everything PDF: https://e-discovery.uk/api/public/library/can-we-collect-only-relevant-data-instead-of-imaging-everything Category: Guide Published: 2026-08-30 Pages: 18 Topics: Forensic collection and imaging Keywords: targeted collection, data collection, ediscovery, digital forensics, proportionality, imaging everything, full image collection, disclosure, preservation, acpo principles, npcc principles, cpr part 35, expert reports, chain of custody, collection risks, selection criteria, digital evidence This guide for UK lawyers examines targeted collection, contrasting it with full-image collection. It details the proportionality case for collecting less data, outlines associated risks, and provides guidance on designing selection criteria. The guide also covers essential forensic disciplines, preservation strategies, and common mistakes in targeted data collection. ### Can You Prove A USB Drive Was Connected Page: https://e-discovery.uk/library/can-you-prove-a-usb-drive-was-connected PDF: https://e-discovery.uk/api/public/library/can-you-prove-a-usb-drive-was-connected Category: Guide Published: 2026-08-30 Pages: 17 Topics: Data theft and exfiltration Keywords: usb connection evidence, usb drive forensics, digital forensics, computer forensics, usb artefact stack, usb device identification, usb connection timing, usb serial number, usb volume identity, usb connection analysis, usb data access, usb connection records, usb connection proof, disclosure, e-discovery, electronic evidence This guide for UK lawyers explains how to prove a USB drive connection through forensic analysis of the artefact stack, identifying specific devices via serials, and establishing connection timing. It also clarifies what connection evidence does not prove, aiding in data theft and exfiltration cases. ### CCTV Evidence Page: https://e-discovery.uk/library/cctv-evidence PDF: https://e-discovery.uk/api/public/library/cctv-evidence Category: Guide Published: 2026-08-30 Pages: 17 Topics: CCTV and physical access evidence Keywords: cctv evidence, video evidence, digital video evidence, cctv preservation, cctv collection, cctv export, cctv authenticity, cctv timeline, cctv clocks, cctv overwrite, cctv retention, digital forensics, dvr, nvr, cloud cameras, doorbell cameras, cpr part 35, expert reports CCTV evidence is time-sensitive and requires immediate action to prevent overwrite. This guide details the recording estate, preservation strategies, export methods, and authenticity considerations for UK litigators, in-house counsel, and investigators. It covers common mistakes, technical limitations, and when to involve a digital forensic expert. ### Citrix VDI And Remote Desktop Where The Evidence Actually Resides Page: https://e-discovery.uk/library/citrix-vdi-and-remote-desktop-where-the-evidence-actually-resides PDF: https://e-discovery.uk/api/public/library/citrix-vdi-and-remote-desktop-where-the-evidence-actually-resides Category: Guide Published: 2026-08-30 Pages: 17 Topics: Servers, NAS and virtual environments Keywords: vdi evidence, remote desktop evidence, citrix evidence, virtual desktop infrastructure, digital forensics, ediscovery, session hosts, golden images, profile stores, non-persistent vdi, persistent vdi, connection logs, endpoint evidence, cpr part 35, expert reports Understanding where evidence resides in Citrix, VDI, and Remote Desktop environments is critical for UK litigators. This guide clarifies the complexities of session hosts, golden images, and profile stores, detailing how to locate and preserve digital evidence effectively in these virtual settings. ### Citrix VDI And Remote Desktop Where The Evidence Actually Resides (1) Page: https://e-discovery.uk/library/citrix-vdi-and-remote-desktop-where-the-evidence-actually-resides-1 PDF: https://e-discovery.uk/api/public/library/citrix-vdi-and-remote-desktop-where-the-evidence-actually-resides-1 Category: Guide Published: 2026-08-30 Pages: 17 Topics: Servers, NAS and virtual environments Keywords: citrix evidence location, vdi evidence location, remote desktop evidence, virtual desktop infrastructure, session host forensics, golden image forensics, profile store forensics, endpoint forensics, non-persistent vdi, persistent vdi, session logs, connection records, digital forensics, cpr part 35 expert reports, chain of custody Understanding where digital evidence truly resides in virtual desktop infrastructure (VDI) and remote desktop environments is crucial for UK litigators. This guide clarifies the complexities of session hosts, golden images, and user profiles, helping practitioners identify and secure relevant data for e-discovery. ### Citrix VDI And Remote Desktop Where The Evidence Actually Resides (2) Page: https://e-discovery.uk/library/citrix-vdi-and-remote-desktop-where-the-evidence-actually-resides-2 PDF: https://e-discovery.uk/api/public/library/citrix-vdi-and-remote-desktop-where-the-evidence-actually-resides-2 Category: Guide Published: 2026-08-30 Pages: 17 Topics: Servers, NAS and virtual environments Keywords: vdi evidence, remote desktop evidence, citrix forensics, digital forensics, e-discovery, session hosts, golden images, profile stores, endpoint evidence, persistent non-persistent vdi, connection logs, cpr part 35 expert reports, electronic evidence, disclosure Understanding where digital evidence resides in Citrix, VDI, and Remote Desktop environments is crucial for UK litigators. This guide details the architectures, persistent versus non-persistent systems, and the actual locations of user data, connection records, and other relevant information, helping practitioners avoid common pitfalls. ### Cloud Evidence Is Not Just Files Page: https://e-discovery.uk/library/cloud-evidence-is-not-just-files PDF: https://e-discovery.uk/api/public/library/cloud-evidence-is-not-just-files Category: Guide Published: 2026-08-30 Pages: 17 Topics: Cloud evidence Keywords: cloud evidence, cloud forensics, digital forensics, ediscovery, disclosure, electronic disclosure, cloud data, cloud documents, cloud files, cloud platforms, cloud services, versions, logs, permissions, sharing links, deleted objects, admin records, metadata Cloud evidence extends beyond files to include versions, logs, permissions, sharing links, deleted objects, configuration, and admin records. These seven layers often contain the critical evidence in a case, proving facts that files alone cannot. Understanding and collecting these layers is crucial for UK litigators. ### Collecting Evidence From Google Workspace Page: https://e-discovery.uk/library/collecting-evidence-from-google-workspace PDF: https://e-discovery.uk/api/public/library/collecting-evidence-from-google-workspace Category: Guide Published: 2026-08-30 Pages: 17 Topics: Forensic collection and imaging, Google Workspace evidence Keywords: google workspace evidence, google workspace forensics, google vault, gmail evidence, google drive evidence, google chat evidence, google meet evidence, ediscovery google, disclosure google, google data collection, google data preservation, google takeout, google api, digital forensics google, pd 57ad, cpr part 31 Understand the forensic collection of Google Workspace evidence for UK litigation. This guide details preservation, collection routes, and common pitfalls across Gmail, Drive, Chat, and Admin data, providing essential insights for legal practitioners. ### Cooperating On Electronic Disclosure Without Giving Away Your Case Page: https://e-discovery.uk/library/cooperating-on-electronic-disclosure-without-giving-away-your-case PDF: https://e-discovery.uk/api/public/library/cooperating-on-electronic-disclosure-without-giving-away-your-case Category: Guide Published: 2026-08-30 Pages: 22 Topics: Electronic disclosure practice Keywords: electronic disclosure cooperation, e-disclosure, disclosure cooperation, electronic disclosure, disclosure review document, drd, pd 57ad, cpr part 31, search terms, custodians, technology assisted review, tar, clawback, production protocols, digital forensics, acpo principles, npcc principles, disclosure strategy Electronic disclosure cooperation is a duty with legal teeth, yet practitioners fear giving away their case. This guide outlines how to share process machinery while safeguarding strategy, covering custodians, search terms, date ranges, and technology-assisted review. ### Coordinating Forensic Collection Across Multiple Offices And Countries Page: https://e-discovery.uk/library/coordinating-forensic-collection-across-multiple-offices-and-countries PDF: https://e-discovery.uk/api/public/library/coordinating-forensic-collection-across-multiple-offices-and-countries Category: Guide Published: 2026-08-30 Pages: 20 Topics: Forensic collection and imaging, Cross-border and data protection Keywords: multi-site collection, cross-border collection, forensic collection, digital evidence collection, international collection, blocking statutes, data transfer restrictions, local counsel, acpo principles, npcc principles, cpr part 35, chain of custody, ediscovery campaign, remote collection, synchronised collection, data consolidation, digital forensics expert, uk lawyers This guide outlines a methodology for coordinating forensic collection across multiple international sites. It addresses legal challenges, data transfers, and synchronisation, providing a framework for consistent evidence gathering in complex, cross-border e-discovery matters. ### CRM Evidence Salesforce HubSpot Page: https://e-discovery.uk/library/crm-evidence-salesforce-hubspot PDF: https://e-discovery.uk/api/public/library/crm-evidence-salesforce-hubspot Category: Guide Published: 2026-08-30 Pages: 17 Topics: Enterprise systems and business records Keywords: crm evidence, salesforce, hubspot, customer relationship management, departing employee, exfiltration, data exfiltration, data deletion, data recovery, pipeline analysis, digital forensics, ediscovery, electronic disclosure, crm data, crm logs, crm notes, solicitation evidence This guide explores CRM evidence from platforms such as Salesforce and HubSpot, examining how these systems record customer relationships and user interactions. It covers data anatomy, histories, logs, collection routes, and common challenges, providing essential insights for UK legal practitioners. ### Deduplication Explained Page: https://e-discovery.uk/library/deduplication-explained PDF: https://e-discovery.uk/api/public/library/deduplication-explained Category: Guide Published: 2026-08-30 Pages: 17 Topics: Processing and review Keywords: deduplication, ediscovery, disclosure, hashes, custodian level deduplication, matter level deduplication, duplicate documents, near duplicates, disclosure protocol, copy evidence, digital forensics, disclosure budget, email deduplication, suppression, disclosure review document, pd 57ad Deduplication reduces data volumes by identifying and suppressing exact copies. This guide explains the mechanics of hashing, the difference between custodian-level and matter-level deduplication, and how to manage suppressed copies for evidential purposes. It addresses common problems and offers practical advice for UK litigators. ### Digital Chain Of Custody A Practical Guide For Lawyers Page: https://e-discovery.uk/library/digital-chain-of-custody-a-practical-guide-for-lawyers PDF: https://e-discovery.uk/api/public/library/digital-chain-of-custody-a-practical-guide-for-lawyers Category: Guide Published: 2026-08-30 Pages: 18 Topics: Chain of custody and defensibility Keywords: digital chain of custody, chain of custody, digital evidence, evidence continuity, custody lifecycle, digital forensics, electronic evidence, acpo principles, npcc principles, cpr part 35, expert reports, expert witness, physical custody, logical custody, tamper evident seals, hash checks, custody records, transfer records Digital chain of custody ensures the integrity and authenticity of electronic evidence. This guide details the lifecycle of digital exhibits, from acquisition to court, covering physical and logical custody, documentation, common mistakes, and how to identify and address breaks in the chain, ensuring evidence remains admissible and reliable. ### Digital Redaction That Cannot Be Reversed Page: https://e-discovery.uk/library/digital-redaction-that-cannot-be-reversed PDF: https://e-discovery.uk/api/public/library/digital-redaction-that-cannot-be-reversed Category: Guide Published: 2026-08-30 Pages: 17 Topics: Production and redaction Keywords: digital redaction, redaction failure, redaction verification, burn-in, sanitisation, metadata redaction, spreadsheet redaction, native file redaction, image redaction, media redaction, disclosure protocol, cpr part 35, expert report, computer forensics, ediscovery, data concealment This guide explains why simple covering fails as digital redaction, outlining how real redaction works through burn-in and sanitisation. It covers verification, hard formats, and common mistakes, helping practitioners ensure redactions are permanent and auditable. ### Document Management Systems In Disclosure Page: https://e-discovery.uk/library/document-management-systems-in-disclosure PDF: https://e-discovery.uk/api/public/library/document-management-systems-in-disclosure Category: Guide Published: 2026-08-30 Pages: 17 Topics: Enterprise systems and business records Keywords: document management systems, dms disclosure, dms evidence, disclosure, cpr part 31, cpr part 35, electronic disclosure, edisclosure, version history, access logs, activity trails, imanage, netdocuments, departing fee earners, dms exfiltration, privilege Document management systems, such as iManage and Net Documents, record every version and interaction with a document. This guide explores their anatomy, histories, and collection methods, offering practical advice for UK litigators on leveraging DMS evidence in disclosure. ### Domain DNS And Hosting Records Page: https://e-discovery.uk/library/domain-dns-and-hosting-records PDF: https://e-discovery.uk/api/public/library/domain-dns-and-hosting-records Category: Guide Published: 2026-08-30 Pages: 17 Topics: Open source, web and log evidence Keywords: domain records, dns records, hosting records, website infrastructure, registrant unmasking, whois, email authentication, spf, dkim, dmarc, spoofing disputes, registrars, nominet, norwich pharmacal, digital forensics, cpr part 35 expert reports, website history, rdap This guide details how to investigate domain, DNS, and hosting records to uncover website ownership and infrastructure history. It covers unmasking registrants, reconstructing domain activity, and addressing email authentication issues, providing practical guidance for UK litigators. ### Door Access Swipe Cards And Building Logs Page: https://e-discovery.uk/library/door-access-swipe-cards-and-building-logs PDF: https://e-discovery.uk/api/public/library/door-access-swipe-cards-and-building-logs Category: Guide Published: 2026-08-30 Pages: 17 Topics: CCTV and physical access evidence Keywords: door access logs, swipe card evidence, building access data, physical presence evidence, badge event logs, access control systems, digital forensics, e-discovery evidence, cctv evidence, time and attendance systems, expert reports cpr part 35, disclosure duties, data retention, forensic collection, access control logs, building logs, access card data, turnstile data Door access, swipe cards, and building logs create a digital diary of physical presence. This guide for UK lawyers explains how to interpret these records, attribute events to individuals, and integrate them into a digital timeline for litigation or investigation, highlighting common pitfalls and expert involvement. ### Email Threading Page: https://e-discovery.uk/library/email-threading PDF: https://e-discovery.uk/api/public/library/email-threading Category: Guide Published: 2026-08-30 Pages: 17 Topics: Processing and review, Email evidence Keywords: email threading, inclusive emails, email review, ediscovery email, email chains, email branches, email authenticity, disclosure protocol, cpr part 35 expert reports, digital forensics email, email production, email evidence, email conversations, email metadata Email threading identifies and groups related emails into conversations, highlighting inclusive messages and branching patterns. This process streamlines e-discovery review by focusing on the most complete communications, while also identifying critical deviations and contested chains. ### ERP Evidence SAP Oracle Page: https://e-discovery.uk/library/erp-evidence-sap-oracle PDF: https://e-discovery.uk/api/public/library/erp-evidence-sap-oracle Category: Guide Published: 2026-08-30 Pages: 17 Topics: Enterprise systems and business records Keywords: erp evidence, sap evidence, oracle evidence, enterprise systems evidence, change documents, audit logs, workflow analysis, procurement fraud, warranty disputes, supply chain disputes, cpr part 35 expert reports, digital forensic expert, e-discovery, electronic disclosure, system of record, purchase to pay Enterprise Resource Planning (ERP) systems, such as SAP and Oracle, are the machine that runs the company, linking every disputed transaction into a documented flow with a change history. This guide explains how to follow the flow, read the changes, and test the approvals for evidence. ### External Storage Devices As Evidence Page: https://e-discovery.uk/library/external-storage-devices-as-evidence PDF: https://e-discovery.uk/api/public/library/external-storage-devices-as-evidence Category: Guide Published: 2026-08-30 Pages: 18 Topics: Data theft and exfiltration Keywords: external storage devices, digital forensics, ediscovery, memory sticks, usb drives, sd cards, portable media, computer forensics, digital evidence, forensic imaging, deleted data recovery, file timestamps, data attribution, disclosure, cpr part 31, pd 57ad External storage devices are crucial evidence sources in UK litigation, revealing copied files, timestamps, and deleted data. This guide details their examination, from intake and imaging to attribution and common pitfalls. It assists practitioners in understanding what these devices disclose and how to interpret their contents. ### Forensic Collection From Corporate File Servers Page: https://e-discovery.uk/library/forensic-collection-from-corporate-file-servers PDF: https://e-discovery.uk/api/public/library/forensic-collection-from-corporate-file-servers Category: Guide Published: 2026-08-30 Pages: 17 Topics: Forensic collection and imaging, Servers, NAS and virtual environments Keywords: file server forensic collection, corporate file server, shared drive forensics, network drive collection, deleted files server, server snapshots, file attribution, metadata server, audit logs server, permissions server, acpo principles, cpr part 35 expert, digital evidence, ediscovery server, sharepoint forensics, onedrive forensics Forensic collection from corporate file servers presents unique challenges compared to device imaging. This guide explores how servers record permissions, audit trails, and metadata, and discusses the attribution problem on shared systems. It provides a playbook for collection, common mistakes, and questions to ask. ### Forensic Collection Of Exchange Online Mailboxes Page: https://e-discovery.uk/library/forensic-collection-of-exchange-online-mailboxes PDF: https://e-discovery.uk/api/public/library/forensic-collection-of-exchange-online-mailboxes Category: Guide Published: 2026-08-30 Pages: 17 Topics: Forensic collection and imaging, Microsoft 365 evidence, Email evidence Keywords: exchange online, mailbox collection, forensic collection, deleted email recovery, email metadata, e-discovery, digital forensics, microsoft 365, office 365, recoverable items, litigation hold, disclosure, pd 57ad, cpr part 31 This guide addresses the forensic collection of Exchange Online mailboxes, detailing how to access all layers of mail, including deleted and archived items, while preserving critical metadata. It covers mailbox anatomy, common mistakes, and the importance of expert involvement for UK litigators. ### Forensic Data Collection Explained For Lawyers Page: https://e-discovery.uk/library/forensic-data-collection-explained-for-lawyers PDF: https://e-discovery.uk/api/public/library/forensic-data-collection-explained-for-lawyers Category: Guide Published: 2026-08-30 Pages: 23 Topics: Forensic collection and imaging Keywords: forensic data collection, digital forensics, e-discovery, data collection, electronic evidence, chain of custody, metadata, hash verification, audit trail, repeatability, source preservation, timestamps, expert evidence, proportionality, crimpr part 19, npcc, fsr, iso Forensic data collection is an evidential act, not an IT task. This guide explains the seven pillars of forensic collection: repeatability, audit trail, timestamps, hash verification, source preservation, metadata, and chain of custody. It covers standards, proportionality, common mistakes, and questions to ask. ### Forensic Image Logical Extraction Or Targeted Collection Page: https://e-discovery.uk/library/forensic-image-logical-extraction-or-targeted-collection PDF: https://e-discovery.uk/api/public/library/forensic-image-logical-extraction-or-targeted-collection Category: Guide Published: 2026-08-30 Pages: 19 Topics: Forensic collection and imaging Keywords: forensic image, logical extraction, targeted collection, ediscovery data acquisition, digital forensics collection, data collection methods, electronic disclosure, disclosure review document, cpr part 31, pd 57ad, custodian data, digital evidence, collection proportionality, cost of collection, chain of custody, digital forensic expert This guide for UK lawyers addresses the critical decision of forensic collection methods: forensic image, logical extraction, or targeted collection. It defines each approach, compares them, and provides a framework for matching the method to evidential need, considering cost, proportionality, and risk. ### GitHub GitLab And Source Code As Evidence Page: https://e-discovery.uk/library/github-gitlab-and-source-code-as-evidence PDF: https://e-discovery.uk/api/public/library/github-gitlab-and-source-code-as-evidence Category: Guide Published: 2026-08-30 Pages: 17 Topics: Enterprise systems and business records Keywords: source code evidence, github evidence, gitlab evidence, git evidence, software forensics, code copying disputes, intellectual property disputes, developer exfiltration, code provenance, digital forensics, commits, repositories, authenticating code history, software development lifecycle, computer forensics, disclosure, electronic evidence, expert witness Source code from platforms like GitHub and GitLab offers a detailed, date-stamped history of development. This guide assists UK litigators, in-house counsel, and investigators in understanding and utilising this digital evidence, covering its anatomy, authentication, and common pitfalls. ### Google Vault In Litigation Page: https://e-discovery.uk/library/google-vault-in-litigation PDF: https://e-discovery.uk/api/public/library/google-vault-in-litigation Category: Guide Published: 2026-08-30 Pages: 17 Topics: Google Workspace evidence Keywords: google vault, vault litigation, vault e-discovery, vault collection, vault export, digital forensics, e-disclosure, electronic disclosure, disclosure protocol, cpr part 35, expert reports, chain of custody, google workspace, google suite, google holds, retention policies Google Vault is a preservation backbone and a bounded collector for Google Workspace evidence. This guide clarifies its strengths, where its reach and fidelity stop, and how to integrate it with independent forensic collection for UK litigation. It addresses common mistakes and technical limitations. ### How To Design Defensible Keyword Searches Page: https://e-discovery.uk/library/how-to-design-defensible-keyword-searches PDF: https://e-discovery.uk/api/public/library/how-to-design-defensible-keyword-searches Category: Guide Published: 2026-08-30 Pages: 17 Topics: Search terms and technology assisted review, Chain of custody and defensibility Keywords: defensible keyword searches, ediscovery search design, search protocol, disclosure review document, drd, search terms, search methodology, keyword search syntax, keyword search operators, keyword search limitations, keyword search negotiation, digital forensic expert, whatsapp data search, teams data search, ocr, structured data Learn to design effective and defensible keyword searches for e-discovery. This guide covers term selection, syntax, negotiation, documentation, and common pitfalls, ensuring your search methodology is robust and withstands scrutiny. ### How To Draft An Electronic Disclosure Production Protocol Page: https://e-discovery.uk/library/how-to-draft-an-electronic-disclosure-production-protocol PDF: https://e-discovery.uk/api/public/library/how-to-draft-an-electronic-disclosure-production-protocol Category: Guide Published: 2026-08-30 Pages: 17 Topics: Production and redaction, Electronic disclosure practice Keywords: electronic disclosure production protocol, production protocol, e-disclosure protocol, disclosure protocol, drafting production protocol, pd 57ad, disclosure review document, drd, metadata fields, load files, document families, email threading, redaction, privilege, clawback, confidentiality, data exchange, electronic disclosure An electronic disclosure production protocol is a crucial early agreement preventing expensive later disputes. This guide details its components, including format, data, protection, and operations clauses. It covers where the protocol sits within the disclosure framework and offers guidance on common mistakes, technical limitations, and when to involve a digital forensic expert. ### Investigating Suspected Employee Data Theft Page: https://e-discovery.uk/library/investigating-suspected-employee-data-theft PDF: https://e-discovery.uk/api/public/library/investigating-suspected-employee-data-theft Category: Guide Published: 2026-08-30 Pages: 17 Topics: Data theft and exfiltration, Employment and departing employees Keywords: employee data theft investigation, data exfiltration, springboard relief, computer forensics, digital forensics, uk gdpr, cpr part 35, data breach, employee monitoring, unauthorised data access, data misappropriation, forensic readiness, injunctions, delivery-up This guide outlines the critical steps for UK litigators, in-house counsel, and investigators dealing with suspected employee data theft. It covers lawful investigation, evidence collection, and legal deployment, emphasising preservation and speed. ### Legal Professional Privilege In Large Electronic Datasets Page: https://e-discovery.uk/library/legal-professional-privilege-in-large-electronic-datasets PDF: https://e-discovery.uk/api/public/library/legal-professional-privilege-in-large-electronic-datasets Category: Guide Published: 2026-08-30 Pages: 17 Topics: Privilege Keywords: legal professional privilege, lpp, litigation privilege, e-discovery privilege, electronic disclosure, disclosure review document, cpr part 31, privilege review, privilege waiver, privilege identification, privilege claims, privilege schedules, redaction, pre-production qc, electronic datasets, large datasets, email threads, chat messages This guide for UK lawyers details how to manage legal professional privilege within large electronic datasets. It covers identifying, protecting, and claiming privilege at scale, addressing waiver risks and common mistakes in electronic discovery workflows. ### Locked Mobile Devices Page: https://e-discovery.uk/library/locked-mobile-devices PDF: https://e-discovery.uk/api/public/library/locked-mobile-devices Category: Guide Published: 2026-08-30 Pages: 17 Topics: Mobile and messaging evidence, Encryption and access Keywords: locked mobile devices, mobile device unlocking, digital forensics, passcode, mobile phone, legal authority, s.49 ripa, cpr part 35, ediscovery, data preservation, evidence access, biometrics, lockouts, wipes, custody, cloud data, expert reports, forensic examination Locked mobile devices present a strategy problem with a technical component. This guide details preservation, access routes, and legal authority, including s.49 RIPA. It covers risk management, common mistakes, and when to involve a digital forensic expert, offering a parallel-tracks framework for practitioners. ### Mac Evidence In Litigation Page: https://e-discovery.uk/library/mac-evidence-in-litigation PDF: https://e-discovery.uk/api/public/library/mac-evidence-in-litigation Category: Guide Published: 2026-08-30 Pages: 18 Topics: Apple and macOS forensics Keywords: mac evidence, macos forensics, apple forensics, mac litigation, digital forensics mac, apfs, filevault, time machine, icloud, apple silicon, mac artefacts, deleted files mac, mac data acquisition, mac expert witness, e-discovery mac, mac disclosure Mac evidence presents unique challenges in litigation, differing significantly from Windows systems. This guide explores macOS forensics, covering APFS, FileVault, Time Machine, and iCloud. It details acquisition, artefact mapping, common mistakes, and when to engage a digital forensic expert for UK legal matters. ### Metadata For Lawyers What It Can And Cannot Prove Page: https://e-discovery.uk/library/metadata-for-lawyers-what-it-can-and-cannot-prove PDF: https://e-discovery.uk/api/public/library/metadata-for-lawyers-what-it-can-and-cannot-prove Category: Guide Published: 2026-08-30 Pages: 17 Topics: Metadata and timestamps Keywords: metadata, digital forensics, ediscovery, disclosure, expert evidence, cpr part 35, document authenticity, data manipulation, backdating, file system metadata, application metadata, communication metadata, metadata preservation, metadata production, load file, electronic disclosure, forensic expert Metadata records specific technical events. Understanding these events, corroborating across sources, and pleading exactly that is crucial. This guide explains metadata families, innocent rewrites, manipulation signatures, and safe reading techniques for UK lawyers. ### Microsoft Purview Or Independent Forensic Collection Page: https://e-discovery.uk/library/microsoft-purview-or-independent-forensic-collection PDF: https://e-discovery.uk/api/public/library/microsoft-purview-or-independent-forensic-collection Category: Guide Published: 2026-08-30 Pages: 17 Topics: Forensic collection and imaging, Microsoft 365 evidence Keywords: microsoft purview, forensic collection, m365 collection, e-discovery collection, disclosure, cpr part 35, expert reports, chain of custody, collection strategy, data collection, microsoft 365, digital forensics, edisclosure, electronic disclosure, collection protocol, forensic examiner This guide helps UK lawyers choose the correct collection route for Microsoft 365 evidence, weighing the benefits of Microsoft Purview against independent forensic collection. It provides a decision framework, discusses hybrid approaches, and explains how to defend the chosen method in court. Common mistakes and technical limitations are also covered. ### Mobile Phone Forensics Page: https://e-discovery.uk/library/mobile-phone-forensics PDF: https://e-discovery.uk/api/public/library/mobile-phone-forensics Category: Guide Published: 2026-08-30 Pages: 17 Topics: Mobile and messaging evidence Keywords: mobile phone forensics, mobile device forensics, mobile evidence, digital forensics, phone data extraction, mobile data recovery, deleted data recovery, encrypted phone access, app evidence, mobile preservation, mobile handling, forensic expert, mobile data, device state, cloud evidence, mobile phone data Mobile phone forensics is governed by extraction level, encryption state, and app architecture. This guide explores these gates, alongside deleted data, preservation, and common mistakes, helping UK lawyers navigate mobile and messaging evidence in litigation. ### NAS Evidence RAID Snapshots Shared Access Logs And Deleted Data Page: https://e-discovery.uk/library/nas-evidence-raid-snapshots-shared-access-logs-and-deleted-data PDF: https://e-discovery.uk/api/public/library/nas-evidence-raid-snapshots-shared-access-logs-and-deleted-data Category: Guide Published: 2026-08-30 Pages: 16 Topics: Servers, NAS and virtual environments, Deleted data and recovery, Open source, web and log evidence Keywords: nas evidence, network attached storage, raid forensics, digital forensics, deleted data recovery, shared drive evidence, access logs, snapshots, electronic disclosure, e-disclosure, computer forensics, data acquisition, forensic imaging, attribution Network-Attached Storage, or NAS, devices are common in offices and homes, holding vast amounts of data. This guide explains their architecture, how evidence is acquired, and what records they keep, including accounts, logs, snapshots, and deleted files. It also covers common mistakes and technical limitations. ### Native Documents PDFs Or Images Which Production Format Page: https://e-discovery.uk/library/native-documents-pdfs-or-images-which-production-format PDF: https://e-discovery.uk/api/public/library/native-documents-pdfs-or-images-which-production-format Category: Guide Published: 2026-08-30 Pages: 17 Topics: Production and redaction Keywords: production format, native documents, pdf production, image production, disclosure protocol, pd 57ad, pd 31b, edisclosure, electronic disclosure, redaction, spreadsheets, presentations, chat messages, media files, load file This guide examines the three families of production formats: native, searchable PDF, and image-plus-load-file. It details what each format preserves or destroys, and how to choose the appropriate format within a disclosure protocol, addressing redaction and technical limitations. ### OCR When Searchable Does Not Mean Accurate Page: https://e-discovery.uk/library/ocr-when-searchable-does-not-mean-accurate PDF: https://e-discovery.uk/api/public/library/ocr-when-searchable-does-not-mean-accurate Category: Guide Published: 2026-08-30 Pages: 17 Topics: Processing and review Keywords: ocr accuracy, searchable pdf, text recognition errors, ocr quality, scanned documents, text layer, disclosure protocol, cpr part 35, expert reports, digital forensics, handwriting ocr, ocr limitations, disclosure review document, ocr disputes, e-discovery ocr, text extraction This guide addresses the accuracy of Optical Character Recognition (OCR) for scanned documents in e-discovery. It covers how OCR works, its limitations, and the impact of text quality on searches. It provides guidance on measuring text quality, handling difficult cases, and incorporating OCR considerations into legal protocols and disclosure. ### OneDrive Evidence Page: https://e-discovery.uk/library/onedrive-evidence PDF: https://e-discovery.uk/api/public/library/onedrive-evidence Category: Guide Published: 2026-08-30 Pages: 17 Topics: Microsoft 365 evidence Keywords: onedrive evidence, onedrive forensics, cloud evidence, digital forensics, onedrive collection, onedrive deletion, onedrive sharing, onedrive sync, onedrive versions, data exfiltration, expert reports, e-discovery, disclosure, cpr part 35, computer forensics, electronic evidence, data recovery, sharepoint evidence OneDrive evidence is complex, involving cloud and device components. This guide details its anatomy, collection strategies, deletion recovery, exfiltration patterns, and common pitfalls, providing essential insights for UK legal professionals. ### Personal Email Accounts In Disclosure Page: https://e-discovery.uk/library/personal-email-accounts-in-disclosure PDF: https://e-discovery.uk/api/public/library/personal-email-accounts-in-disclosure Category: Guide Published: 2026-08-30 Pages: 17 Topics: Email evidence Keywords: personal email accounts disclosure, webmail disclosure, email disclosure, disclosure personal accounts, personal email collection, disclosure obligations, cpr part 31, ediscovery, digital forensics, forensic collection, self-collection, custodian email, email evidence, disclosure guidance, email accounts, disclosure rules Personal email accounts often contain disclosable business content. This guide outlines the challenges of accessing such accounts, the legal duties involved, and practical collection routes. It details verification methods, privacy concerns, and the role of digital forensic experts in ensuring complete and defensible disclosure. ### Planning An On Site Digital Evidence Collection Page: https://e-discovery.uk/library/planning-an-on-site-digital-evidence-collection PDF: https://e-discovery.uk/api/public/library/planning-an-on-site-digital-evidence-collection Category: Guide Published: 2026-08-30 Pages: 19 Topics: Forensic collection and imaging Keywords: on-site digital evidence collection, digital forensics site visit, digital evidence acquisition planning, computer forensics, electronic evidence collection, digital evidence preservation, acpo digital evidence principles, npcc digital evidence principles, cpr part 35 expert reports, chain of custody, data collection planning, ediscovery collection, forensic imaging, data seizure, digital evidence handling, on-site data collection Planning an on-site digital evidence collection requires careful consideration of access, authority, credentials, and equipment. This guide details the necessary pre-visit reconnaissance and execution steps to ensure a successful collection day, minimising disruption and securing evidence properly. ### Preparing A Forensic Collection Protocol Page: https://e-discovery.uk/library/preparing-a-forensic-collection-protocol PDF: https://e-discovery.uk/api/public/library/preparing-a-forensic-collection-protocol Category: Guide Published: 2026-08-30 Pages: 20 Topics: Forensic collection and imaging Keywords: collection protocol, forensic collection protocol, ediscovery collection, digital forensics protocol, data collection plan, acpo principles, npcc digital evidence, cpr part 35 expert reports, chain of custody, custodians, data sources, date ranges, privilege, personal data, uk gdpr, disclosure review document, drd methodology, expert witness protocol A forensic collection protocol is a written plan ensuring defensible data collection. This guide details its anatomy, covering scope, exclusions, execution, and contingencies, and provides guidance on drafting and agreement for UK legal professionals. ### Preserving Social Media Evidence Page: https://e-discovery.uk/library/preserving-social-media-evidence PDF: https://e-discovery.uk/api/public/library/preserving-social-media-evidence Category: Guide Published: 2026-08-30 Pages: 17 Topics: Preservation and legal holds, Open source, web and log evidence Keywords: social media evidence, evidence preservation, digital forensics, social media capture, evidential weight, authentication, deleted content, cpr part 35, expert reports, chain of custody, social media platforms, account records, ip logs, self-download archives, screenshots, admissibility, disclosure, preservation letter Social media evidence, with its inherent impermanence, requires specific preservation strategies. This guide outlines methods for capturing posts, profiles, and stories, from self-download archives to provider records, and addresses authentication, common mistakes, and technical limitations for UK legal professionals. ### Proportionality In EDisclosure When Is Enough Enough Page: https://e-discovery.uk/library/proportionality-in-edisclosure-when-is-enough-enough PDF: https://e-discovery.uk/api/public/library/proportionality-in-edisclosure-when-is-enough-enough Category: Guide Published: 2026-08-30 Pages: 22 Topics: Costs and early case assessment, Electronic disclosure practice Keywords: proportionality, edisclosure, disclosure, disclosure review document, drd, cpr part 31, pd 57ad, electronic disclosure, cost proportionality, volume proportionality, evidential value, technical difficulty, importance proportionality, disclosure strategy, disclosure obligations, disclosure disputes, digital forensics Proportionality in eDisclosure is crucial for UK legal professionals. This guide examines the five key factors - volume, cost, importance, technical difficulty, and evidential value - that inform the 'stopping decision'. It provides practical advice, worked examples, and strategic considerations for managing electronic disclosure effectively and defensibly. ### Recovering Historical Documents From Snapshots And Volume Shadow Copies Page: https://e-discovery.uk/library/recovering-historical-documents-from-snapshots-and-volume-shadow-copies PDF: https://e-discovery.uk/api/public/library/recovering-historical-documents-from-snapshots-and-volume-shadow-copies Category: Guide Published: 2026-08-30 Pages: 17 Topics: Windows forensics, Deleted data and recovery Keywords: volume shadow copies, snapshots, historical documents, document recovery, version histories, digital forensics, ediscovery, windows shadow copy, server snapshots, nas snapshots, hypervisor snapshots, cloud versioning, data recovery, electronic disclosure, disclosure review document, cpr part 31, pd 57ad, deleted data This guide for UK lawyers details how historical document states can be recovered from Windows Volume Shadow Copies, server snapshots, and cloud platform version histories. It covers the layers of data preservation, methods for differencing, common mistakes, and when to engage a digital forensic expert. ### Remote Forensic Collection When Can It Be Defensible Page: https://e-discovery.uk/library/remote-forensic-collection-when-can-it-be-defensible PDF: https://e-discovery.uk/api/public/library/remote-forensic-collection-when-can-it-be-defensible Category: Guide Published: 2026-08-30 Pages: 19 Topics: Forensic collection and imaging, Chain of custody and defensibility Keywords: remote forensic collection, defensibility, e-discovery, digital forensics, remote data collection, chain of custody, custodian issues, cross-border data, security considerations, privacy considerations, collection protocol, forensic examiner, endpoint verification, hash at source, session logging, uk lawyers, disclosure, search orders Remote forensic collection is defensible when specific methods are followed, not simply by geography. This guide details the five disciplines, models, and considerations for secure, defensible remote collections, addressing human factors, technical limitations, and cross-border issues. ### SharePoint As A Disclosure Source Page: https://e-discovery.uk/library/sharepoint-as-a-disclosure-source PDF: https://e-discovery.uk/api/public/library/sharepoint-as-a-disclosure-source Category: Guide Published: 2026-08-30 Pages: 17 Topics: Microsoft 365 evidence, Electronic disclosure practice Keywords: sharepoint disclosure, sharepoint evidence, sharepoint ediscovery, disclosure source, electronic disclosure, sharepoint forensics, sharepoint collection, sharepoint versions, sharepoint permissions, sharepoint deletion, sharepoint metadata, sharepoint sites, sharepoint libraries, cpr part 35, expert reports SharePoint presents unique challenges and opportunities for electronic disclosure. This guide explores its architecture, including libraries, versions, permissions, and deletion, to help practitioners understand and manage this complex data source effectively in UK litigation. ### Should A Computer Be Imaged While Running Or Switched Off Page: https://e-discovery.uk/library/should-a-computer-be-imaged-while-running-or-switched-off PDF: https://e-discovery.uk/api/public/library/should-a-computer-be-imaged-while-running-or-switched-off Category: Guide Published: 2026-08-30 Pages: 21 Topics: Forensic collection and imaging Keywords: computer imaging, live acquisition, offline acquisition, dead-box acquisition, digital forensics, volatile data, encryption, bitlocker, filevault, npcc principle 2, cpr part 35, chain of custody, expert reports, digital evidence, memory capture, forensic acquisition, computer evidence, ediscovery This guide explores the critical decision of whether to image a computer live or offline, focusing on volatile data, encryption, and the implications for forensic collection. It provides a framework for UK lawyers to navigate this complex choice, ensuring evidential integrity. ### Should Backup Systems Be Searched For Disclosure Page: https://e-discovery.uk/library/should-backup-systems-be-searched-for-disclosure PDF: https://e-discovery.uk/api/public/library/should-backup-systems-be-searched-for-disclosure Category: Guide Published: 2026-08-30 Pages: 17 Topics: Electronic disclosure practice Keywords: backup systems, disclosure, ediscovery, preservation, proportionality, digital forensics, restoration, archive, data retention, cpr part 31, pd 57ad, electronic disclosure, spoliation, custodian This guide explores the complex issue of searching backup systems for electronic disclosure in UK litigation. It addresses preservation, proportionality, and the decision framework for when such searches are necessary, particularly when backups hold the sole remaining evidence. Practical advice on targeted restoration and arguing the point is included. ### Signal And Ephemeral Messaging Page: https://e-discovery.uk/library/signal-and-ephemeral-messaging PDF: https://e-discovery.uk/api/public/library/signal-and-ephemeral-messaging Category: Guide Published: 2026-08-30 Pages: 17 Topics: Mobile and messaging evidence Keywords: ephemeral messaging, signal messages, disappearing messages, ephemeral app evidence, ephemeral chat, message preservation, digital forensics, forensic expert, adverse inference, disclosure duties, cpr part 31, mobile forensics, telegram messages, snapchat messages, whatsapp messages, residue, counterpart capture, corporate governance This guide for UK lawyers addresses ephemeral messaging evidence, including Signal, Telegram, and Snapchat. It covers preservation duties, corporate governance, and how digital forensic examination can still uncover residue and counterpart evidence, even from messages designed to disappear. ### Slack EDiscovery Page: https://e-discovery.uk/library/slack-ediscovery PDF: https://e-discovery.uk/api/public/library/slack-ediscovery Category: Guide Published: 2026-08-30 Pages: 17 Topics: Slack and Teams, Electronic disclosure practice Keywords: slack ediscovery, slack disclosure, slack data collection, slack retention, slack exports, slack dms, slack channels, slack messages, slack forensics, slack evidence, slack legal, slack review, slack api, slack edits, slack deletions, chat ediscovery, collaboration platform ediscovery, instant messaging ediscovery Slack's architecture, including channels, DMs, and retention tiers, significantly influences what evidence is available for electronic disclosure. This guide details the data model, collection methods, and common pitfalls, helping practitioners navigate Slack e-discovery challenges. ### SMS And IMessage Evidence Page: https://e-discovery.uk/library/sms-and-imessage-evidence PDF: https://e-discovery.uk/api/public/library/sms-and-imessage-evidence Category: Guide Published: 2026-08-30 Pages: 17 Topics: Mobile and messaging evidence Keywords: sms evidence, imessage evidence, text message evidence, mobile phone forensics, digital forensics, deleted messages, message recovery, message authentication, cpr part 35 expert reports, operator records, cloud sync, timestamps, attribution, rcs messages, mobile device forensics, electronic evidence This guide explores the complexities of SMS and iMessage evidence, detailing message databases, cloud sync, and deleted layers. It covers timestamps, attribution, and recovery realities, offering insights for UK litigators, in-house counsel, and investigators. ### Technical Preparation For A Disclosure Case Management Conference Page: https://e-discovery.uk/library/technical-preparation-for-a-disclosure-case-management-conference PDF: https://e-discovery.uk/api/public/library/technical-preparation-for-a-disclosure-case-management-conference Category: Guide Published: 2026-08-30 Pages: 23 Topics: Disclosure and PD 57AD Keywords: disclosure case management conference, disclosure cmc, technical preparation, e-disclosure, e-discovery, disclosure review document, drd, pd 57ad, cpr part 31, disclosure guidance hearing, dgh, search methodology, technology assisted review, tar, digital forensics, electronic disclosure, electronic discovery, disclosure Preparing for a Disclosure Case Management Conference requires technical understanding of systems, data volumes, and search methodologies. This guide outlines key briefing areas, from preservation to production formats, helping practitioners navigate the complexities of PD 57AD and present a well-prepared case to the court. ### Technology Assisted Review For UK Lawyers Page: https://e-discovery.uk/library/technology-assisted-review-for-uk-lawyers PDF: https://e-discovery.uk/api/public/library/technology-assisted-review-for-uk-lawyers Category: Guide Published: 2026-08-30 Pages: 17 Topics: Search terms and technology assisted review Keywords: technology assisted review, tar, predictive coding, continuous active learning, cal, disclosure, e-disclosure, e-discovery, cpr part 35, disclosure review document, drd, machine learning review, document review, electronic disclosure Technology-Assisted Review (TAR) amplifies human judgement by ranking documents. Its defensibility relies on the training record and validation statistics, both of which are built, not assumed. This guide covers models, training, validation, and its place in legal protocols and tool chains. ### The Missing Evidence Problem Page: https://e-discovery.uk/library/the-missing-evidence-problem PDF: https://e-discovery.uk/api/public/library/the-missing-evidence-problem Category: Guide Published: 2026-08-30 Pages: 17 Topics: Custodians and data mapping Keywords: missing evidence, missing documents, missing data, deleted evidence, deleted documents, deleted data, evidence recovery, data recovery, preservation duties, adverse inference, litigating the gap, disclosure, ediscovery, digital forensics, forensic investigation, data destruction, data loss, electronic evidence This guide addresses the problem of missing evidence in UK litigation, detailing how to prove what should exist, find where it went, and litigate the resulting gap. It covers preservation duties, recovery maps, and the legal consequences of absence. ### Understanding And Controlling EDisclosure Costs Page: https://e-discovery.uk/library/understanding-and-controlling-edisclosure-costs PDF: https://e-discovery.uk/api/public/library/understanding-and-controlling-edisclosure-costs Category: Guide Published: 2026-08-30 Pages: 20 Topics: Costs and early case assessment, Electronic disclosure practice Keywords: edisclosure costs, electronic disclosure costs, disclosure costs management, edisclosure budgeting, edisclosure cost control, edisclosure pricing, edisclosure bills, edisclosure quotes, edisclosure review costs, edisclosure cost reduction, edisclosure provider selection, edisclosure mistakes, edisclosure red flags, edisclosure questions, edisclosure expert Understanding and controlling eDisclosure costs is crucial for UK litigators. This guide details the six cost stages, the multiplication chain, and ten control levers. It covers budgeting, reading provider quotes, and common mistakes to help manage disclosure expenses. ### Using Generative AI Responsibly In Electronic Disclosure Page: https://e-discovery.uk/library/using-generative-ai-responsibly-in-electronic-disclosure PDF: https://e-discovery.uk/api/public/library/using-generative-ai-responsibly-in-electronic-disclosure Category: Guide Published: 2026-08-30 Pages: 17 Topics: AI and synthetic media, Electronic disclosure practice Keywords: generative ai disclosure, ai electronic disclosure, genai edisclosure, ai edisclosure, ai in disclosure, pd 57ad, disclosure review document, drd, prompt engineering, ai verification, ai hallucination, ai privilege, ai redaction, ai summarisation, disclosure protocol, uk gdpr, data protection ai, computer forensics lab This guide explores the responsible application of generative AI in electronic disclosure, covering prompt engineering, human verification, and defensibility. It addresses the guidance landscape, common mistakes, and practical considerations for UK lawyers. Topics include relevance, privilege, summarisation, and redaction support. ### Virtual Machines As Evidence Page: https://e-discovery.uk/library/virtual-machines-as-evidence PDF: https://e-discovery.uk/api/public/library/virtual-machines-as-evidence Category: Guide Published: 2026-08-30 Pages: 18 Topics: Servers, NAS and virtual environments Keywords: virtual machines, vm evidence, e-discovery, digital forensics, hyper-v, vmware, snapshots, virtual disks, historical states, deleted vms, hidden vms, hypervisor logs, backup catalogues, evidence acquisition, disclosure, litigation, uk lawyers, computer forensics Virtual machines present unique challenges and opportunities as evidence in UK litigation. This guide explains their anatomy, defensible acquisition, and the recovery of historical states from snapshots and backups. It also covers hypervisor logs, hidden or deleted VMs, and common mistakes, providing practical questions and a checklist for practitioners. ### Website Web Server And Application Logs Page: https://e-discovery.uk/library/website-web-server-and-application-logs PDF: https://e-discovery.uk/api/public/library/website-web-server-and-application-logs Category: Guide Published: 2026-08-30 Pages: 17 Topics: Servers, NAS and virtual environments, Open source, web and log evidence Keywords: web logs, application logs, website logs, digital forensics, ediscovery, user journey reconstruction, page state, attribution, log retention, log collection, cpr part 35 expert reports, disclosure, server logs, cdn logs, waf logs, ip address, chain of custody, web server logs Website and application logs record every request, enabling reconstruction of user activity. This guide details how these layered logs prove page state and attribution, outlining collection, preservation, and common pitfalls for UK litigators. ### What Evidence Can Be Recovered From A Windows Computer Page: https://e-discovery.uk/library/what-evidence-can-be-recovered-from-a-windows-computer PDF: https://e-discovery.uk/api/public/library/what-evidence-can-be-recovered-from-a-windows-computer Category: Guide Published: 2026-08-30 Pages: 20 Topics: Windows forensics, Deleted data and recovery Keywords: windows forensics, digital evidence, computer forensics, deleted files, usb history, login records, browsing history, execution traces, event logs, forensic timeline, ediscovery, expert witness, disclosure, cpr part 35, crimpr part 19, artefacts, data recovery, electronic evidence Windows computers record far more than users create, offering a rich source of evidence for UK litigators and investigators. This guide details the types of digital artefacts recoverable, from deleted files to system logs, and how they build a timeline for legal proceedings. ### What Evidence Can Be Recovered From A Windows Computer (1) Page: https://e-discovery.uk/library/what-evidence-can-be-recovered-from-a-windows-computer-1 PDF: https://e-discovery.uk/api/public/library/what-evidence-can-be-recovered-from-a-windows-computer-1 Category: Guide Published: 2026-08-30 Pages: 20 Topics: Windows forensics, Deleted data and recovery Keywords: windows forensics, windows computer evidence, digital forensics, computer forensics, deleted files recovery, usb device history, login activity, browsing history, program execution, event logs, digital evidence timeline, e-discovery, expert witness, civil procedure rules part 35, criminal procedure rules part 19, forensic examination Windows computers retain a significant amount of data beyond what users intentionally create. This guide details the types of digital evidence recoverable from these systems, such as deleted files, login activity, program execution traces, and internet browsing history, which can be crucial in legal investigations. ### What Happens During EDiscovery Processing Page: https://e-discovery.uk/library/what-happens-during-ediscovery-processing PDF: https://e-discovery.uk/api/public/library/what-happens-during-ediscovery-processing Category: Guide Published: 2026-08-30 Pages: 17 Topics: Processing and review, Electronic disclosure practice Keywords: ediscovery processing, data processing, processing disputes, processing decisions, edisclosure processing, disclosure protocol wording, ediscovery checklist, digital forensic expert, mobile data processing, chat data processing, cloud data processing, structured data processing, denisting, exception reporting, reconciliation, cpr part 35 expert reports, chain of custody, processing errors E-discovery processing is the critical, often overlooked, stage between data collection and document review. This guide demystifies the process, explaining how decisions about exceptions, de-NISTing, and filters shape the final document set, ensuring defensibility and accuracy in electronic disclosure. ### What Is A Forensic Hash And Why Does It Matter Page: https://e-discovery.uk/library/what-is-a-forensic-hash-and-why-does-it-matter PDF: https://e-discovery.uk/api/public/library/what-is-a-forensic-hash-and-why-does-it-matter Category: Guide Published: 2026-08-30 Pages: 20 Topics: Chain of custody and defensibility Keywords: forensic hash, hash values, digital evidence integrity, md5, sha-1, sha-256, electronic evidence authentication, hash collisions, digital forensics, ediscovery integrity, court evidence hashes, file integrity verification, electronic disclosure, expert witness digital, disclosure review document, cpr part 31, pd 57ad, acpo guidelines A forensic hash is a digital fingerprint proving a file's identity and integrity. This guide explains how hashing works, its practical applications, and its role in legal proceedings, including common misconceptions and how to present hash evidence in court. ### WhatsApp Evidence Page: https://e-discovery.uk/library/whatsapp-evidence PDF: https://e-discovery.uk/api/public/library/whatsapp-evidence Category: Guide Published: 2026-08-30 Pages: 17 Topics: Mobile and messaging evidence Keywords: whatsapp evidence, whatsapp forensics, whatsapp discovery, whatsapp disclosure, mobile forensics, digital forensics, deleted whatsapp messages, whatsapp groups, whatsapp authentication, whatsapp backups, whatsapp data, electronic evidence, e-disclosure, e-discovery, cpr part 35, expert reports WhatsApp evidence presents unique challenges due to its architecture, encryption, and deletion features. This guide explores databases, backups, linked devices, and the implications of 'for-me' and 'for-everyone' deletion, offering insights into authentication and preservation for UK legal professionals. ### Why Lawyers Should Test Search Terms Before Agreeing Them Page: https://e-discovery.uk/library/why-lawyers-should-test-search-terms-before-agreeing-them PDF: https://e-discovery.uk/api/public/library/why-lawyers-should-test-search-terms-before-agreeing-them Category: Guide Published: 2026-08-30 Pages: 17 Topics: Search terms and technology assisted review Keywords: search term testing, search terms, disclosure review document, drd, search protocol, pd 57ad, cpr part 31, hit counts, sampling, elusion, precision, overlap, nulls, ediscovery, e-disclosure, digital forensics, forensic expert Lawyers must test search terms to avoid signing a list they have not run, transforming search negotiation from adjectives into arithmetic. This guide covers hit counts, sampling, elusion testing, and using the numbers for refinement and PD 57AD negotiation. ### CFL Digital Forensics Services Brochure Page: https://e-discovery.uk/library/cfl-digital-forensics-services-brochure PDF: https://e-discovery.uk/api/public/library/cfl-digital-forensics-services-brochure Category: Guide Published: 2026-08-29 Pages: 10 Topics: Expert evidence and reports, Electronic disclosure practice Keywords: digital forensics, e-discovery, expert witness, computer forensics, mobile forensics, cloud forensics, corporate investigations, litigation support, electronic disclosure, civil litigation, criminal defence, regulatory investigations, employment disputes, data preservation, forensic examination, digital evidence, expert report, npcc This guide details digital forensics and e-discovery services, including expert witness support. It covers independent forensic examination of digital evidence, from seizure to courtroom, for civil, criminal, regulatory, and corporate matters, ensuring technical reliability and legal defensibility. ### Completing The Disclosure Review Document A Technical And Legal Guide Page: https://e-discovery.uk/library/completing-the-disclosure-review-document-a-technical-and-legal-guide PDF: https://e-discovery.uk/api/public/library/completing-the-disclosure-review-document-a-technical-and-legal-guide Category: Guide Published: 2026-08-29 Pages: 21 Topics: Disclosure and PD 57AD, Electronic disclosure practice Keywords: disclosure review document, drd, e-disclosure, e-discovery, disclosure, civil procedure rules, cpr part 31, pd 57ad, forensic examiner, digital forensics, disclosure guidance, disclosure practice, litigation disclosure, disclosure obligations, disclosure review, disclosure process The Disclosure Review Document is a crucial component of UK e-disclosure, requiring input from the client, e-discovery specialist, and forensic examiner. This guide provides a field-by-field breakdown, addresses common mistakes, and offers practical advice for its joint completion and negotiation. ### Control Of Electronic Documents What Lawyers Need To Investigate Page: https://e-discovery.uk/library/control-of-electronic-documents-what-lawyers-need-to-investigate PDF: https://e-discovery.uk/api/public/library/control-of-electronic-documents-what-lawyers-need-to-investigate Category: Guide Published: 2026-08-29 Pages: 23 Topics: Custodians and data mapping Keywords: control of electronic documents, document control, e-disclosure, disclosure obligations, legal test for control, subsidiaries documents, parent companies documents, employee personal devices, personal accounts, contractor documents, consultant documents, outsourced provider documents, managed services documents, cloud platforms, former staff documents, third party documents, cross-border disclosure, digital forensic expert Understanding "control" of electronic documents is crucial for UK lawyers. This guide explores the legal test, categories of documents, and investigation steps, covering subsidiaries, employees, cloud platforms, and third parties. It assists practitioners in identifying and managing relevant electronic information. ### Digital Forensic Evidence What Every Defence Lawyer Needs To Know Computer Forensics Lab Page: https://e-discovery.uk/library/digital-forensic-evidence-what-every-defence-lawyer-needs-to-know-computer-foren PDF: https://e-discovery.uk/api/public/library/digital-forensic-evidence-what-every-defence-lawyer-needs-to-know-computer-foren Category: Guide Published: 2026-08-29 Pages: 22 Topics: Expert evidence and reports Keywords: digital forensic evidence, defence lawyer, computer forensics, digital artefacts, forensic process, digital evidence types, forensic methodology, expert witness, evidence preservation, criminal defence, civil litigation, electronic evidence, e-discovery, disclosure Digital forensic evidence is crucial in modern legal cases. This guide details the forensic process from seizure to courtroom, common types of digital evidence, and the expert's role. It provides essential knowledge for defence lawyers navigating digital artefacts. ### Early Data Assessment Before Disclosure Costs Escalate Page: https://e-discovery.uk/library/early-data-assessment-before-disclosure-costs-escalate PDF: https://e-discovery.uk/api/public/library/early-data-assessment-before-disclosure-costs-escalate Category: Guide Published: 2026-08-29 Pages: 26 Topics: Costs and early case assessment, Electronic disclosure practice Keywords: early data assessment, eda, early case assessment, eca, disclosure costs, e-disclosure, e-discovery, disclosure, data volume, custodians, file types, duplication, privileged material, data protection, digital forensics, computer forensics, relativity, pd 57ad Early data assessment (EDA) is a crucial step for UK lawyers to understand the scope and nature of electronic data before committing to full disclosure. It helps estimate volumes, identify custodians, and predict potential costs, ensuring informed decisions and efficient management of e-discovery processes. ### EDisclosure Or Digital Forensics Choosing The Correct Approach Page: https://e-discovery.uk/library/edisclosure-or-digital-forensics-choosing-the-correct-approach PDF: https://e-discovery.uk/api/public/library/edisclosure-or-digital-forensics-choosing-the-correct-approach Category: Guide Published: 2026-08-29 Pages: 23 Topics: Electronic disclosure practice Keywords: edisclosure vs digital forensics, forensic examination triggers, disclosure forensic needs, digital forensics, edisclosure, forensic acquisition, forensic preservation, data collection methods, uk gdpr, proportionality, privilege, cpr part 31, pd 57ad, acpo, metadata, chain of custody This guide clarifies the distinction between e-disclosure and digital forensics, outlining their definitions, overlaps, and critical differences. It provides a decision tree, forensic triggers, and practical workflows for UK litigators, in-house counsel, and investigators to choose the appropriate method for evidence collection and examination. ### Electronic Disclosure Explained A Practical Guide For UK Lawyers Page: https://e-discovery.uk/library/electronic-disclosure-explained-a-practical-guide-for-uk-lawyers PDF: https://e-discovery.uk/api/public/library/electronic-disclosure-explained-a-practical-guide-for-uk-lawyers Category: Guide Published: 2026-08-29 Pages: 34 Topics: Electronic disclosure practice Keywords: electronic disclosure, edisclosure, digital forensics, e-disclosure guide, uk lawyers, civil procedure rules, cpr part 31, pd 57ad, disclosure review document, drd, electronic disclosure questionnaire, edq, legal holds, preservation, collection, metadata, privilege, uk gdpr Electronic disclosure in UK litigation involves identifying, preserving, collecting, processing, reviewing, producing, presenting, and disposing of electronically stored information. This guide covers the legal duties, rules, and sanctions, alongside practical advice for managing e-disclosure effectively in England and Wales. ### Finding The Evidence A Lawyers Map Of Modern Electronic Data Sources Page: https://e-discovery.uk/library/finding-the-evidence-a-lawyers-map-of-modern-electronic-data-sources PDF: https://e-discovery.uk/api/public/library/finding-the-evidence-a-lawyers-map-of-modern-electronic-data-sources Category: Guide Published: 2026-08-29 Pages: 25 Topics: Custodians and data mapping Keywords: electronic data sources, data identification, e-discovery, digital forensics, electronic evidence, data mapping, custodian questionnaire, it systems questionnaire, data volatility, data preservation, disclosure review document, cpr part 35, cpr part 31, pd 57ad, disclosure duty, litigation hold, computers, laptops Identifying all potentially relevant electronic data sources is a fundamental legal duty in UK litigation. This guide provides a lawyer's map, detailing various data types, their volatility, and practical methods for comprehensive identification, including questionnaires and cross-checks, to ensure a defensible e-discovery process. ### How To Build A Defensible EDisclosure Strategy At The Start Of A Case Page: https://e-discovery.uk/library/how-to-build-a-defensible-edisclosure-strategy-at-the-start-of-a-case PDF: https://e-discovery.uk/api/public/library/how-to-build-a-defensible-edisclosure-strategy-at-the-start-of-a-case Category: Guide Published: 2026-08-29 Pages: 27 Topics: Chain of custody and defensibility, Electronic disclosure practice Keywords: edisclosure strategy, defensible strategy, edisclosure workflow, edisclosure process, disclosure strategy, early disclosure, disclosure review document, drd, disclosure models, issue-source matrix, data map, custodian selection, forensic triage, early data assessment, search design, collection plan, review protocol, preservation Building a defensible eDisclosure strategy is crucial for UK litigators. This guide details the ten steps, from day-one preservation and data mapping to search design and review protocols, ensuring a robust and compliant approach to electronic disclosure. ### Identifying The Right Custodians In Electronic Disclosure Page: https://e-discovery.uk/library/identifying-the-right-custodians-in-electronic-disclosure PDF: https://e-discovery.uk/api/public/library/identifying-the-right-custodians-in-electronic-disclosure Category: Guide Published: 2026-08-29 Pages: 23 Topics: Custodians and data mapping, Electronic disclosure practice Keywords: custodian identification, electronic disclosure, e-disclosure, custodians, disclosure review document, drd, custodian interview, shared mailboxes, former employees, organisational data, service accounts, departmental repositories, tiering, pd 57ad, cpr part 31, digital forensics Identifying custodians is central to electronic disclosure in UK litigation. This guide clarifies the concept of a custodian, distinguishes custodial from non-custodial sources, and provides a methodical approach to selecting and interviewing custodians, including handling difficult categories and common pitfalls. ### Initial Disclosure What Should Be Provided And What Should Be Preserved Page: https://e-discovery.uk/library/initial-disclosure-what-should-be-provided-and-what-should-be-preserved PDF: https://e-discovery.uk/api/public/library/initial-disclosure-what-should-be-provided-and-what-should-be-preserved Category: Guide Published: 2026-08-29 Pages: 19 Topics: Disclosure and PD 57AD, Preservation and legal holds Keywords: initial disclosure, disclosure obligations, document preservation, e-disclosure, cpr part 31, pd 57ad, disclosure review document, electronic disclosure, disclosure bundle, disclosure guidance, digital forensics, litigation disclosure, disclosure mistakes, disclosure checklist, e-discovery, disclosure requirements Initial Disclosure in UK litigation requires lawyers to understand two distinct obligations: what to provide in the bundle and what to preserve from the whole universe of data. This guide clarifies the legal framework, common pitfalls, and best practices for defensible Initial Disclosure. ### Known Adverse Documents In The Digital Age Page: https://e-discovery.uk/library/known-adverse-documents-in-the-digital-age PDF: https://e-discovery.uk/api/public/library/known-adverse-documents-in-the-digital-age Category: Guide Published: 2026-08-29 Pages: 20 Topics: Disclosure and PD 57AD Keywords: adverse documents, known adverse documents, disclosure duty, e-disclosure, digital evidence, electronic documents, search methodology, employee knowledge, unusual repositories, identification programme, handling adverse finds, common mistakes, digital forensics, pd 57ad, cpr part 31, disclosure review document This guide addresses the identification of known adverse documents in the digital age, focusing on methodology, employee knowledge, and unusual repositories. It outlines an identification programme, discusses handling adverse finds, and highlights common mistakes. ### PD57AD Explained For Litigation Lawyers Page: https://e-discovery.uk/library/pd57ad-explained-for-litigation-lawyers PDF: https://e-discovery.uk/api/public/library/pd57ad-explained-for-litigation-lawyers Category: Guide Published: 2026-08-29 Pages: 23 Topics: Disclosure and PD 57AD Keywords: pd 57ad, disclosure, litigation, e-disclosure, disclosure review document, drd, known adverse documents, cooperation, initial disclosure, disclosure models, digital forensics, cpr part 31, technology assisted review, tar, electronic disclosure, disclosure duties, disclosure workflow PD 57AD governs disclosure in UK litigation, outlining duties for parties and lawyers. It covers the workflow from initial disclosure to the five Models, emphasising cooperation and technology. The guide also addresses common mistakes and variants for less complex claims. ### The Electronic Discovery Reference Model For UK Litigation Teams Page: https://e-discovery.uk/library/the-electronic-discovery-reference-model-for-uk-litigation-teams PDF: https://e-discovery.uk/api/public/library/the-electronic-discovery-reference-model-for-uk-litigation-teams Category: Guide Published: 2026-08-29 Pages: 24 Topics: Electronic disclosure practice Keywords: edrm, electronic discovery reference model, e-discovery, disclosure, uk litigation, cpr part 31, pd 57ad, disclosure review document, drd, digital forensics, identification, preservation, collection, processing, review, production, acpo, npcc The Electronic Discovery Reference Model (EDRM) provides a structured approach to electronic disclosure in UK litigation. This guide details each stage from identification to production, using a worked commercial dispute to illustrate the process and highlight key considerations for UK legal teams. ### The First EDisclosure Meeting 50 Questions Lawyers Should Ask Page: https://e-discovery.uk/library/the-first-edisclosure-meeting-50-questions-lawyers-should-ask PDF: https://e-discovery.uk/api/public/library/the-first-edisclosure-meeting-50-questions-lawyers-should-ask Category: Guide Published: 2026-08-29 Pages: 23 Topics: Electronic disclosure practice Keywords: edisclosure meeting, disclosure meeting, first edisclosure meeting, edisclosure questions, disclosure questionnaire, edisclosure interview, it architecture, custodians, devices, cloud services, deleted data, data retention, data backups, data preservation, privacy, data protection, privilege, third parties The first e-disclosure meeting is crucial for UK lawyers to understand a client's data landscape. This guide provides 50 questions across key areas like IT systems, data custodians, and preservation actions, helping to convert answers into practical steps for electronic disclosure. ### UK Digital Forensics for US Litigation Teams Page: https://e-discovery.uk/library/uk-digital-forensics-for-us-litigation-teams PDF: https://e-discovery.uk/__l5e/assets-v1/3e6f3b1a-d2be-4700-8bc2-bb2df896b1c0/UK-Digital-Forensics-for-US-Litigation-Teams.pdf Category: Brochure Published: 2026-08-29 Pages: 6 Topics: US litigation support, Cross-border and data protection, Forensic collection and imaging A capability overview written for US counsel who need evidence that sits in the United Kingdom handled properly, then delivered into the review workflow their firm already runs. The brochure explains where a London forensic laboratory fits alongside a US trial team: your firm keeps legal strategy, privilege calls, review, production and the client relationship, while we take responsibility for defensible acquisition and forensic interpretation on the ground. It maps a typical matter across five stages, from preservation strategy and UK custodian collections through analysis, structured handoff and litigation support. Coverage includes onsite and remote imaging of laptops, servers and endpoints, mobile and cloud extraction, enterprise systems, and investigations into trade secret theft and employee departures, where deleted files, USB transfers and personal cloud uploads usually decide the case. A dedicated section addresses cross-border risk: UK GDPR and Data Protection Act obligations, lawful transfer of personal data to the United States, proportionality, and how these are reconciled with FRCP obligations and preservation duties. The brochure also details Relativity ready exports and load files, hashing and documented provenance, chain of custody records that survive challenge, sworn declarations, technical explanations for motion practice and expert testimony in US proceedings. Contact routes, London laboratory credentials, accreditations and response times are included so a US team can instruct quickly when a deadline is already running. ### UK Digital Forensics Support For US Litigation Teams Page: https://e-discovery.uk/library/uk-digital-forensics-support-for-us-litigation-teams PDF: https://e-discovery.uk/api/public/library/uk-digital-forensics-support-for-us-litigation-teams Category: Guide Published: 2026-08-29 Pages: 6 Topics: US litigation support Keywords: uk digital forensics, us litigation, cross-border evidence, computer forensics, digital evidence, ediscovery support, forensic analysis, uk data collection, mobile forensics, cloud evidence, trade secret litigation, employee departure, technical evidence, data preservation, expert support, london forensics This guide details specialist UK digital forensics support for US litigation teams, covering evidence collection, forensic analysis, and integration with existing e-discovery workflows. It addresses situations where evidence resides in the UK, on physical devices, or requires expert interpretation. ### What Is A Reasonable Electronic Search Page: https://e-discovery.uk/library/what-is-a-reasonable-electronic-search PDF: https://e-discovery.uk/api/public/library/what-is-a-reasonable-electronic-search Category: Guide Published: 2026-08-29 Pages: 24 Topics: Search terms and technology assisted review Keywords: reasonable electronic search, e-discovery, disclosure, electronic disclosure, cpr 31.7, pd 31b, pd 57ad, search terms, keywords, custodians, date ranges, analytics, technology-assisted review, tar, proportionality, defensibility, acpo principles, digital evidence Understanding a reasonable electronic search is crucial for UK litigators. This guide details the levers involved, such as custodians, dates, keywords, and analytics, alongside the legal standards of CPR 31.7, PD 31B, and PD 57AD, to ensure defensibility and avoid common pitfalls. ### Digital Forensics Services Page: https://e-discovery.uk/library/digital-forensics-services PDF: https://e-discovery.uk/__l5e/assets-v1/aa891a74-7e56-4e9d-9fdb-bfdf5b668792/CFL-Digital-Forensics-Services-Brochure.pdf Category: Brochure Published: 2026-08-26 Pages: 10 Topics: Forensic collection and imaging, Expert evidence and reports, Chain of custody and defensibility A complete guide to how Computer Forensics Lab handles electronic evidence for UK litigation, internal investigations and regulatory work. The brochure walks through the full lifecycle: scoping and preservation advice before a single device is touched, forensic imaging of laptops, servers, removable media and network shares, and targeted extraction from mobile handsets, Microsoft 365, Google Workspace, Slack, Teams and WhatsApp. It explains how collected material is processed, de-duplicated, filtered by custodian, date range and keyword, then loaded into hosted review in Relativity, with technology assisted review available on larger matters. Later sections cover analysis work that goes beyond document review: recovery of deleted files, tracing data exfiltration to USB devices and personal cloud accounts, reconstructing user activity timelines, and interpreting artefacts that show who did what and when. The brochure sets out our reporting standards, including CPR Part 35 compliant expert reports, witness statements, exhibit bundles and testimony at hearings. Throughout, it details the controls that keep evidence defensible: hash verification, documented chain of custody, secure UK based storage, ISO 17025 aligned laboratory practice, ICO registration and UK GDPR compliant handling of personal data. Practical detail on turnaround times, remote and onsite acquisition across the UK, out of hours response, fixed fee options and how instructions are opened rounds out the document, so solicitors, in house counsel and compliance teams can judge fit before making contact.