Chain of Custody for Digital Evidence: A Practical Checklist — Herarx Blog

Chain of Custody for Digital Evidence: A Practical Checklist

A gap in the chain of custody is all opposing counsel needs. This checklist covers collection, storage, access and transfer for photos, files, emails and messages.

November 27, 2025
Chain of Custody for Digital Evidence: A Practical Checklist
Back to blog

Chain of custody is the documented, unbroken account of who had a piece of evidence from the moment it was collected until it is presented. For physical items that means bags, seals and signatures. For digital evidence it means answering, for every file, four questions at every step: who, what, when, and was it changed. Here is the checklist.

At collection

  • Record the date, time, location and collector at the time, not afterwards.
  • Capture into the record system directly where possible — a photo uploaded from the phone into the matter, rather than taken, stored on the device and copied later.
  • Preserve the original: no cropping, no editing, no re-saving in a different format. If a working copy is needed, make it explicitly and label it.
  • Assign a unique reference on arrival that cannot be reused or reordered. Sequential IDs minted by the system beat anything typed.
  • Note the source: the device, the account, the person who handed it over.

For emails and messages

  • Keep the original message with its headers — sender, recipients, Message-ID, server timestamps. A forwarded copy is a new message and proves little.
  • Export threads as complete units, not screenshots, where the platform allows.
  • For chat apps, capture the account, the device and the export method alongside the content.

In storage

  • Files must not be editable in place. A new version is a new file with its own timestamp.
  • Every view and download should be logged with the person and the time.
  • Access should be restricted to named individuals per matter — not "everyone in the team".
  • Encryption at rest, with keys held separately from the data.
  • Storage timestamps should come from the server, not from a workstation clock that can be changed.

On transfer

  • Record who received what, when, and how (portal share, encrypted transfer, physical media).
  • Prefer giving access over sending copies: a portal share can be revoked and is logged; an attachment cannot and is not.
  • Where a copy must be sent, record a hash of the file before it leaves so the recipient can verify it is unchanged.

The record itself

  • The audit trail must be written by the system and not editable by the people it describes.
  • It should be exportable as a chronology alongside the evidence list.
  • The evidence list should show, per item: reference, description, collected by, collected at, source, current location, every access and every transfer.

Common breaks

Copying files to a laptop "to work on them". Renaming to something tidier. Emailing an exhibit to a colleague who then forwards it. Photos sitting in a camera roll for a week before upload. None of these is malicious; all of them open a gap. The discipline is collect into the record, number on arrival, never copy out — expanded in chain of custody in the digital age and working from a phone in the field.