Who Accessed Or Downloaded A Confidential Document
17 pages · 23 min read
This guide, 'Who Accessed Or Downloaded A Confidential Document', is for UK lawyers, in-house counsel and investigators.
- Data theft and exfiltration
This guide, 'Who Accessed Or Downloaded A Confidential Document', is for UK lawyers, in-house counsel and investigators.
Guide · 17 pages · 23 min read · Published 2026-08-31
This guide, 'Who Accessed Or Downloaded A Confidential Document', is for UK lawyers, in-house counsel and investigators. It covers reading access trails across cloud platforms, file servers and end point s. The guide explains what Share Point, One Drive, Google Drive, SaaS, file servers, DMS and end point s record, and what each record proves, such as view, open, d own load, sync, print and share. It addresses retention, licensing, and the clocks that decide survival of logs. It also details how to attribute an account to a person, where else evidence lives, common mistakes, technical limitations, and provides questions to ask. The guide includes a checklist, red flags, and frequently asked questions, such as whether access can be proved after deletion.
Read this guide on your phone, browse guides by topic or go back to the full PDF library.
17 pages · 23 min read
This guide, 'Who Accessed Or Downloaded A Confidential Document', is for UK lawyers, in-house counsel and investigators.
Published by Computer Forensics Lab on 2026-08-31. Original material of the practice, free to read, cite and download. The authority behind this subject is ICO guide to the UK GDPR, which you should read alongside this guide. See every guide's author and source.
Prefer a PDF that matches this page exactly? Download the current text as a PDF, generated from the wording shown here, including any later corrections.
DOCUMENT ACCESS EVIDENCE · A GUIDE FOR UK LAWYERS Who Accessed or Downloaded a Confidential Document Reading Access Trails Across Cloud Platforms, File Servers and Endpoints COMPUTER FORENSICS LAB
§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM ESTABLISHED 2007 · LONDON ISO 17025-ALIGNED PROCEDURES ACCESS-LOG ANALYSIS
§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: access is logged, and logs are not names 03 Cloud platforms: what Share Point, One Drive, Google Drive and SaaS record 04 File servers, DMS and end point s: the on-premises and local record 05 What each record proves: view, open, d own load, sync, print and share 06 Retention, licensing and the clocks that decide survival 07 From account to person: attribution and deployment 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist
§ 01 · ORIENTATION Executive summary THE HEADLINE POINT: FILEACCESSISRECORDEDATTHEPLATFORM, THE SERVER AND THE END POINT, EACHNAMINGANACCOUNTRATHERTHANAPERSONANDEACHONITS OWNRETENTIONCLOCK: EXPORTTHELOGSFIRST, READWHATEACHEVENTACTUALLY MEANS, THENJOINACCOUNTTOPERSONWITHINDEPENDENTCORROBORATION
§ 02 · FIRST PRINCIPLES The problem in plain English: access is logged, and logs are not names
§ 03 · THECLOUDRECORD Cloud platforms: what Share Point, One Drive, Google Drive and SaaS record
§ 04 · THEON - PREMISESANDLOCALRECORD File servers, DMS and end point s: the on-premises and local record
§ 05 · WHATEACHEVENTPROVES What each record proves: view, open, d own load, sync, print and share
§ 06 · THECLOCKS Retention, licensing and the clocks that decide survival
§ 07 · FROMACCOUNTTOPERSON From account to person: attribution and deployment 99
§ 6's clocks), and leak inquiries where the access population narrows the candidates: the finding drafted to
§ 08 · THEWIDERMAP Source architecture: where else the evidence lives QUESTION SESSION COPY + PLATFORM END POINT PHYSICAL DELETED/ AUDIT LOG ARTEFACTS LAYER EXPIRED SIGN-IN / DOWNSTREAM LAYER RECIPIENT
§ 09 · IN THE WILD Worked examples EXAMPLE1 · THEBOARDPAPERANDTHEFORTY - ONEACCOUNTS EXAMPLE2 · THESERVERTHATWASNEVERLISTENING EXAMPLE3 · THE ACCESS THAT WAS AP REVIEW, ANDTHEDISCIPLINARYTHATWAS WITHDRAWN
§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations
§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent Ask your e Discovery / forensic provider SUGGESTED WORDING · AC CESS - RECORDPRESER VAT I ON AND DISCLOSURE REQUEST
§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The access-investigation checklist Red flags When to involve a digital forensic expert
§ 13 · COMMON QUESTIONS Frequently asked questions Can we find out who opened a document on Share Point? How long do access logs last? The file server has no access logs. Is the trail cold? The log says my client's account accessed the record. Is that the end of it? Can access to a document be proved after it was deleted? Someone photographed the screen. Can that be traced?
§ 14 · REFERENCE Glossary Sources and authoritative references DISCLAIMER
§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY
17 pages · 25 min read
This guide, 'Data Exfiltration to Cloud Storage', is prepared by Computer Forensics Lab for UK lawyers, in-house counsel and investigators.
17 pages · 23 min read
This guide, USBCONNECTIONEVIDENCE · A GUIDE FOR UK LAWYERS, addresses the question, 'Can You Prove a USB Drive Was Connected?' It details the artefact stack where connection is recorded, how to identify the specific device using serials and volume identity, and how to establish timing, including first, last, and in-between connections.
Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.