The Polish criminal procedure is known to various legal tools for obtaining evidence. The content of the evidence from personal sources shall be disclosed and secured at all times during the hearing (as appropriate: witness, suspect and accused, expert). Different procedural actions may apply to factual evidence.
In the case of digital evidence, these opportunities are very diverse, especially because of their specific technical and organisational circumstances. It is clear that ‘appropriate’ procedural instruments should be used in order to obtain digital evidence.
When selecting them, it is important to bear in mind what kind of data is to be used for evidence purposes, where they are located and who is their disposal.
Digital content can be acquired for procedural purposes in several essential ways. After first, through direct criminal activities undertaken by law enforcement representatives (especially in the course of inspection, search and detention of items).
After second, indirectly: through process or voluntary cooperation with external entities with data (including those providing a variety of related services). This may be the case, for example, in the case of a call for voluntary data release or the use of a procedural eavesdrop for a service subscriber.
After third, double indirect: through cooperation with the competent authorities of other countries or persons third (where international legal assistance instruments or voluntary cooperation can serve).
Considerations on process instruments for obtaining digital content are universal for all such evidence. The main purpose of this chapter is to discuss the various legal instruments available in Polish criminal proceedings for obtaining digital evidence for procedural purposes.
This will enable the formulation and identification of appropriate legal bases for the acquisition of such material, depending on the specific situations and taking into account the associated limitations. Next, This will also allow possible proposals for amendments to the existing legislation.
2.2. Processed digital evidence acquisition instruments
2.2.1. Review
There is no doubt about the overall acceptability of securing digital evidence in the course of the examination. Based on Article 207(1) An inspection of the place, person or thing shall be carried out “if necessary”. It may also be necessary to seek to secure digital content from their physical media.
The examination is not regulated by law and results from the tactical-technical framework defined in forensics.
The examination is therefore based on an examination of the place, the thing (or body of a person) in order to know their characteristics and properties in the context of their relevance to the outcome of the case or to disclose another source or means of evidence[1].
The purpose of the investigation is also formulated in the intra-police guidelines as ‘disclosure and safeguarding of traces of the crime or their media at the scene, to a person or items likely to be related to the crime, which may serve as evidence sources in the course of the proceedings’[2].
From the point of view of the law enforcement authorities, there is no doubt that there are no statutory procedural guarantees that could limit the examination activities (as in the case of, for example, searches).
The procedural law allows you to conduct an examination of places, things, persons or corpses. This list is closed and does not foresee the possibility of reviewing digital data understood as a content disconnected from the physical medium.
In the case of viewing activities, digital data must not be seen as their object, but as a forensic trace – a feature of the elements being inspected (e.g. CD/DVD or hard disk). The purpose of examining such cases should not be to examine the content of the data, but only to safeguard it.
The analysis of the digital evidence should then be commissioned to perform a properly qualified expert. The concept of digital data security in the course of the examination should generally mean the execution of their criminal copy (unless a decision has been made to secure the medium – then it is the subject of the security).
The rules on criminal data protection are described in Chapter third.
However, in reality, disclosing and securing digital evidence in the course of viewing the site (especially the scene) is not very common. On the one hand, This is due to the characteristics of the criminal offences related to computer crime: viewing of the scene in general is relatively rare in such cases.
On the other hand, Whereas the parties to the correct forensic protection of digital evidence require adequate preparation of the substantive and non-standard inspection equipment.
Therefore, where electronic equipment or data media are disclosed, they are more often protected in their entirety and subsequently subject to an inspection of the items or directed directly to the expert.
From a procedural point of view, aside from the question of the appropriateness of securing physical computer equipment, this practice is acceptable.
More often there is a physical examination of computer devices and data media, then conducted as an inspection of things.
However, this activity is often carried out incorrectly in terms of forensics: the examination of the physical data media consists in de facto of launching the medium and reviewing (and reporting) the displayed data content.
The conduct carried out in such a way cannot be considered to have been carried out in a correct criminal way – moreover, such interference of the officer with secure equipment may, depending on technological circumstances, lead to a non-explicit change in the data structure.
In the context of the review, we should also mention a separate problem: the need for procedural protection of digital content from other sources – e.g. information on websites that are content of network disks or other remotely accessible resources.
In the current state of the law, there is no specific process for this service, and the attempt to do so by search involves other specific problems for this activity. This may be the reason why website content is often “secured” in the viewing mode.
Inspections are an evidentiary process (which is not ensured, for example, by describing the content of the website in a business note), while statutory rules for conducting them are very universal.
However, such an examination is not correct under the current rules. As already indicated, only place, thing, and person (or corpse) can be inspected. According to the existing interpretation of these concepts, none of these categories can be referred to websites. The content displayed on the screen does not constitute “things” or even “places” that can be viewed.
These categories are also not suitable for viewing digital content.
This thesis appears to be correct also on the basis of a systemic interpretation of the procedural law: there is no chapter 23 kpk a provision allowing appropriate application of the provisions on the examination of data, as it does Article 236a kpk in relation to the provisions of the chapter 25 kpk.
If the opposite position were considered correct, this would undermine the sense of the provision Article 236a in general, as this would mean that it is unnecessary also in the context of searching and stopping things. In the mid-years 90.
The 20th century recommendations of the Council of Europe included a clear statement that the data recorded on the computer medium is not a thing and does not meet the characteristics attributed to the objects, and therefore there is no legal basis for applying the provisions concerning the search or detention of objects to them.[3].
In view of the above, it is justified to formulate a separate procedural action relating to the safeguarding of digital evidence. If such a request were too far-reaching, it would at least be justified to introduce a clear possibility of viewing digital content in a similar way as it does. Article 236a to search and keep things.
The relevant proposals for legislative amendments are set out in the summary of this Chapter.
2.2.2. Searching and stopping
Methods for the process of obtaining digital evidence are often subject to consideration in the context of the provisions on the search and detention of items[4]. This is one from basic procedural institutions allowing law enforcement authorities to directly, technically secure evidence stored on electronic media. At the same time, the legal basis for carrying out such activities is, compared with the regulation on the examination, more complicated and includes many procedural guarantees for persons third.
In the light of the content Article 236a kpk has no doubt that the provisions of the chapter 25 kpk (detention and search) shall apply mutatis mutandis to the controller and user of the device containing the information or information system in relation to the data stored in that device or system or on the medium at his disposal or use, including correspondence sent electronically.
Once again, it is important to highlight the important distinction between data media (physical computer equipment – regardless of its type) and the data itself, seen as material separated from them. These. first are, in the full sense of the word, things.
Their security does not require reference in the legal basis of this action Article 236a kpk.
If a decision to stop physical computer equipment is made, this can be done as in the case of any other object: stop after having requested a voluntary issue based on Article 217 kpk or after finding a search conducted on the basis Article 219 kpk or, in cases of urgency, Article 220(3) kpk.
However, if only data in isolation from their vehicle (e.g. by making a copy of data) are to be covered by the protection, the legal basis should be supplemented by a link with Article 236a kpk. This point is essential and its clear emphasis will avoid unnecessary repetitions. The following considerations will address digital material acquisition by search and the issue of its release by the authorising officer will be discussed Next,.
Objectives of the search under Article 219 kpk indicates that it may be conducted, among others, ‘(...) in order to find things that may constitute evidence in a case or are subject to prosecution’.
With regard to premises and other places, and thus information systems, a search may be made, provided there are reasonable grounds to believe that the suspect or the said items are there.
By applying this provision to digital data on the basis of Article 236a kpk is also allowed to search media, devices and information systems for stored data. The search of the medium should be understood as an opportunity to access the contents already stored on it in the course of the operations undertaken on the site of the search.
The search should in principle be conducted on the basis of an appropriate order from the court or prosecutor (Article 220(2) kpk).
Only in cases of urgency may it be conducted on the basis of an order from the head of the unit or after the presentation of a business card, the action shall be subject to subsequent approval by the court or prosecutor (Article 220(3) kpk).
The search order should clearly indicate the purpose of this action and specify the type of things wanted as precisely as possible. It is rightly pointed out that in the justification, it is appropriate to state the circumstances giving rise to the presumption that the items sought are in a given place.[5].
It is worth noting that in Polish procedural practice these guidelines are not always implemented. The justifications for the search provisions too often include only routine assertions of the necessity of conducting a search “in order to find and retain items related to the crime or possession of which is prohibited”.
The justifications for approving such an action are generally limited to the finding that it was ‘reasonable and compatible with the provisions of kpk’.
This practice, although contrary to the rules of the criminal procedure, does not significantly affect the conduct of the proceedings, since such a procedural error does not, unfortunately, constitute a basis for appeal, nor is it relevant to the technical reliability of the evidence secured in the course of the action.
However, the document layer must not be forgotten – a protocol must be drawn up from the search (Article 143(1)(3)(6) kpk, taking account of guidelines resulting from Article 148, and Article 229 kpk). Its content may be very important for the subsequent assessment of the technical correctness of the safeguarding of evidence in the light of the criteria specified in the framework of forensic computing.
With regard to the actual conduct of the search, if data carriers, information systems or other electronic devices are found during the search, they may be searched and secured by making copies of the data or by stopping the vehicle in its entirety.
The possibility of searching the IT system at the disposal of the person conducting the search is determined by the expressis verbis Article 236a kpk. Controversy is raised by the application of search rules to advanced computer systems.
With the current state of the art of ICT networks, it is very common that the device being searched is remotely connected to others, which may also contain relevant evidence.
Both local network disks, devices located in the same place, and connections to remote IT systems, or even (now very often) with foreign data-processing service providers (connecting with the tested device only through a dedicated application or web browser) are involved.[6].
Several potential proposals were formulated in the literature so far. Described in this context two The main options of the procedure are based on a broader interpretation of the current rules. first The option includes the concept of allowing an enlarged search.
It would take place when, in the course of the search of the IT system (the original system), it turns out that relevant evidence is found in another system to which access is possible through the primary system.
second the option is to carry out a so-called remote search, which is carried out from a computer located at the premises of the police unit, but without informing the user of the "searched" IT system[7].
With regard to the concept of ‘expanded search’, access to other non-research premises through the information networks can be justified by the analogy to the extension of the ‘traditional’ search to the premises of the premises of the premises concerned if necessary[8].
However, it should be pointed out firmly that the procedural search operation has been formulated in the Code of Criminal Procedure as a public action – in principle, not only the preparation and delivery of an adequate provision of the search, but also the notification of the person to whom the search is to take place, even before the start of the operation (Article 224 kpk).
If, during the search of the IT system (original) it turns out that it is possible to access the resources in another computer (secondary system) through the IT network, but the person with whom the search is carried out is not at the same time the holder of this system – the ‘automatic’ extension of the search is not legally permissible.
In order to conduct a proper search, the ‘further’ IT system should be found and the relevant provisions applied to it.[9]. In the light of the content Article 220 and Article 224 the person to whom the search is to be carried out must be informed of the search, even if there is an urgent situation.
Except for obvious problems regarding possible breach of national jurisdiction[10], the problem of the implementation of such an information obligation can therefore be postponed at most over time.
It is also difficult to give a reliable basis for Article 224(3) kpk, since the terms ‘household’ or ‘neighbor’ referred to in the provision will not have equivalents among the persons present at the place of operation of the original IT system
This legal situation creates practical difficulties, clearly limiting the ability of law enforcement authorities. In the light of the existing rules, it is not permitted to obtain material from external sources (e.g. Internet services) from the user by searching the information system (e.g. a computer belonging to a suspected person).
Therefore, it is also not permitted to process the contents stored on external servers, even if the user account is “automatically logged in”. The media of such data are not within the meaning of Article 236a kpk, in the ‘disposal’ of the person in whom the search is carried out.
This situation does not change the content Article 19(2) The Convention on Cybercrime, which is binding on the parties to adopt the legal measures needed to enable the competent authorities to ‘enlarge the search or similar methods of access to another system immediately if, when they search or access similar methods to a particular IT system or part of it (...), they have reasonable grounds to believe that the data sought are in or in another IT system in their territory and that such data can be legally accessed from or accessible to the original system.’ The provisions of the Convention are only mandatory. Polish legislation is not formally contrary to it, although limited only to the extent that the "extension" of the search takes place in subsequent IT systems at the disposal of the same entity.
So, going back to the second of these concepts, it is also unacceptable to carry out a ‘remote’ search. The remote search described in literature is essentially the use of hacking techniques by law enforcement authorities, without the knowledge of the data controller.
There is no doubt that, from a criminal point of view, such action offers many advantages: hypothetically, it allows the conductor to have completely unhindered access to data collected in the IT system, without alerting the person concerned and ignoring the data protection measures it uses.
In the light of existing rules, it is possible to accept such practices as operational and investigative activities (and therefore in particular on the basis of Article 19(6)(3) Police Act[11])[12]. This issue goes beyond the procedural aspects of digital evidence, and therefore beyond the scope of this publication.
However, it is not possible to use such invasive techniques as part of a search operation, and therefore under Polish legislation the phrase "remote search" is misleading. Nor should remote access be confused with the situation in question. Under Article 32 Cybercrime Convention.
It applies only to the access of services to open sources on foreign servers and to data from closed sources but made available by voluntary consent of the person entitled to have them.
The existing limitations of the search institution in the context of secondary IT systems may require legislative intervention. Many foreign legal systems (including European ones) have regulations that allow the conduct of various, more or less interference in the laws of individuals, forms of remote searches of computer systems 13.
The Polish criminal procedure in this respect continues to provide a fairly comprehensive guarantee of the protection of the rights of the entities in which the search is carried out. Any decision to change this situation should be taken through an extended expert and social debate.
This would require consideration of where modern limits of respect for individual rights should be pursued.
Problems include not only the possible limitation of procedural guarantees but also jurisdictional issues. With the extension of the search to other remote access, IT systems can easily be found to be located on foreign servers. In practice, it is so common – especially in the context of the high popularity of cloud storage network services.
__________________________________________
[1] A. Sakowicz (ed.), Code of Criminal Procedure. Commentary, Warsaw 2016, p. 551. Cf. Supreme Court judgment 16 July 2009, reference no. V KK 20/09, Legal Information Service Wolters Kluwer, LEX nr. 51962
[2] section 42 KGP guidelines
[3] Council of Europe Recommendation No R(95)[13] on the problems of the criminal procedure with regard to information technologies with 1995
[4] A. Lach, Fighting illegal content on the Internet, Toruń 2015, p. 26.
[5] D. Świecki (ed.), Code of Criminal Procedure. Commentary, t. I, Warsaw 2018, p. 828.
[6] Lt. J. Kosiński, Paradigms of Crime, du. Difin, 2015, p. 203.
[7] Lt. J. Kosiński, Paradigms of Crime, du. Difin, 2015, p. 203.
[8] A. Adamski, Crime in Cyberspace, 2007, p. 81.
[9] A. Lach, Search..., op.cit., p. 74
[10] This would be the case in the case of even an unconscious, “extension” of the search conducted under the Polish law for a system located abroad (e.g. including servers processing data within the “remote disk” available in the so-called cloud).
[11] Act dated 6 April 1990 About the Police (Journal of Laws of 2020, item 360 as amended).
[12] J. Kosiński, Paradigms..., op.cit., p. 203.
[13] P. Opitek, Selected aspects of the collection of digital evidence in criminal matters [in:] Prosecution and Law’ 2018, No 7-8, p. 73 .
The article comes from the book Lewulis Peter, Digital evidence – forensic theory and practice in Polish criminal proceedings, Warsaw University Publishing House, 2021, p. 87-95