Locked Mobile Devices
17 pages · 21 min read
Locked mobile devices present a strategy problem with a technical component.
- Mobile and messaging evidence
- Encryption and access
This guide addresses the strategic and technical challenges presented by locked mobile devices in UK legal contexts.
Guide · 17 pages · 21 min read · Published 2026-08-30
Written specifically for UK lawyers navigating digital evidence, this text addresses the strategic and technical challenges of recovering critical data from encrypted mobile handsets before any passcode attempts are made. It examines immediate device state management, physical custody, and critical risk controls surrounding biometrics, lockouts, and automated device wipes. The analysis covers the legal grounds governing access, including client consent, contractual authority, judicial compulsion, and s.49 RIPA notices, supported by CPR Part 35 expert reports and full chain-of-custody documentation. To overcome technical barriers such as the BFU wall, it introduces a parallel-tracks framework that ranks access routes by realism while mapping alternative source architecture, including cloud account backups, paired computers, and network providers. Legal teams are provided with practical interrogatories, suggested drafting, red flags, and control checklists to evaluate risks such as exotic unlocking services, custodian self-disclosure, or factory-reset devices. Ultimately, the material equips practitioners to execute lawful, forensically sound ensemble strategies while preventing catastrophic data loss.
Read this guide on your phone, browse guides by topic or go back to the full PDF library.
17 pages · 21 min read
Locked mobile devices present a strategy problem with a technical component.
Published by Computer Forensics Lab on 2026-08-30. Original material of the practice, free to read, cite and download. See every guide's author and source.
Prefer a PDF that matches this page exactly? Download the current text as a PDF, generated from the current wording of the guide, including any later corrections.
LOCKEDMOBILEDEVICES · A GUIDE FOR UK LAWYERS Locked Mobile Devices Preservation, Access Routes, Legal Authority and the Decisions That Must Be Made Before Anyone Tries the Passcode COMPUTER FORENSICS LAB DISCOVERY. UK
§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM ESTABLISHED 2007 · LONDON ISO 17025-ALIGNED PROCEDURES LOCKED-DEVICE ASSESSMENT LAWFUL ACCESS & ENSEMBLE STRATEGY CPR PART 35 EXPERT REPORT S FULL CHAIN-OF-CUSTODY DOCUMENTATION
§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: the wall that is some time s a door 03 First decisions: state, custody and the things nobody must do 04 The access routes, ranked by realism 05 Legal authority: consent, contract, compulsion and s.49 RIPA 06 Risk management: attempts, biometrics, lockouts and wipes 07 Strategy: the parallel-tracks framework 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist
§ 01 · ORIENTATION Executive summary THE HEADLINE POINT: ALOCKEDDEVICEISASTRATEGYPROBLEMWITHATECHNICAL COMPONENT, ANDTHESTRATEGYHASPARALLELTRACKS
§ 02 · FIRST PRINCIPLES The problem in plain English: the wall that is some time s a door
§ 03 · HOURONE First decisions: state, custody and the things nobody must do
§ 04 · THEROUTES The access routes, ranked by realism ROUTE REALISM · WHAT GOVERNS IT
§ 05 · AUTHORITY Legal authority: consent, contract, compulsion and s.49 RIPA
§ 06 · NOTBREAKINGIT Risk management: attempts, biometrics, lockouts and wipes
§ 07 · THEPLAN Strategy: the parallel-tracks framework
§ 08 · THEWIDERMAP Source architecture: where else the evidence lives EVIDENCE LOCKED HANDSET CLOUD COMPUTER PAIRED COUNTERPARTS / DELETED / (IF ACCOUNT BACKUPS COMPUTERS PROVIDERS RECOVERABLE OPENED)
§ 09 · IN THE WILD Worked examples EXAMPLE1 · THECLAUSETHATOPENEDTHEPHONE EXAMPLE2 · THEBFUWALLANDTHEENSEMBLETHATWENTROUNDIT EXAMPLE3 · THEREFUSALTHATTESTIFIED
§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations
§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent Ask your e Discovery / forensic provider
§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The locked-device checklist Red flags When to involve a digital forensic expert
§ 13 · COMMON QUESTIONS Frequently asked questions Can a court really order someone to hand over their passcode? How long should we keep a device we cannot currently open? Is it worth paying for exotic unlocking services? The custodian offers to unlock it himself and show us the messages. Acceptable? What if the device wipes itself during exam in at i on? Does a factory-reset device end the inquiry?
§ 14 · REFERENCE Glossary Sources and authoritative references DISCLAIMER
§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY
19 pages · 25 min read
This guide for UK lawyers explains how iOS devices can be compromised by spyware, stalkerware, or misused features.
18 pages · 26 min read
Android app data forensics requires understanding an open ecosystem, where each app is its own world.
Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.