Process aspects of digital evidence acquisition in criminal proceedings. Part 2
Back to the insights archive
Publications

Process aspects of digital evidence acquisition in criminal proceedings. Part 2

Process wiretap In the era of electronic communications, the principles and possibilities of obtaining digital evidence should be considered with particular attention based on the provisions of the chapter.

Process wiretap In the era of electronic communications, the principles and possibilities of obtaining digital evidence should be considered with particular attention based on the provisions of the chapter.

26 kpk (control and fixation of conversations).

The mode described there is relatively strict, but for some content its application...

2.2.3. Process wiretap

In the era of electronic communications, the principles and possibilities of obtaining digital evidence should be considered with particular attention based on the provisions of the chapter. 26 kpk (control and fixation of conversations).

The method described there is relatively strict, but for some content, its use will be the only possible means of obtaining them.

It is worth noting that in the Polish legal system they are known two essential forms of eavesdropping: process, based on the provisions of the chapter 26 kpk, and outside the process, carried out in the framework of operational and investigative activities (by services empowered to do so under separate provisions)[1].

The operational work issues are not the subject of this discussion, and therefore this information is purely signalling. The process listening can be carried out passively (by passive interception of ongoing communication) or active (by using offensive techniques – e.g. using malicious software in a listening device).

Both options should be considered on a procedural basis for digital evidence.

However, the possibility of using a process wire is subject to a number of limitations. After first, that institution may be used only in proceedings concerning prohibited acts listed exhaustively under Article 237(3) kpk. Most of the types of actions identified there are associated with computer crime.

Nevertheless, there may be a real need in many of them to consolidate digital communication, even if it is not related to the modus operandi of perpetrators. The additional restriction is also due to Article 237(1)(2) kpk the requirement that the hearing be ordered by the court. The order of the court should take the form of an order.

Historically, the process wiretap primarily included the content of telephone calls. With the development of telecommunications techniques, its use naturally expanded into exchanged text messages (SMS).

Currently, this institution can also apply to digital telephony and any other electronic communication channels (modern communication tools operate on the basis of the transmission of message content in the form of so-called digital data packages).

Legally, extending the use of wiretap to further technological solutions is possible in the light of content Article 241 kpk, ordering the proper application of the provisions of the Chapter 26 kpk “for the control and preservation by technical means of the content of other conversations or communications, including electronic correspondence”.

This provision plays a similar role in the context of procedural eavesdropping as Article 236a kpk in the context of searching and stopping things: allows to control communication other than telephone, for example via the Internet using any communicators or e-mails[2] .

Scope of application of the Chapter 26 kpk therefore includes all data in the transfer between the sender and the recipient[3] . This applies equally to all content transmitted in this way, including e-mail or voice communication using VoIP technology[4] .

It is therefore important to distinguish between the data transmitted (in transfer) and the data already transmitted and stored on media. This breakdown has already been mentioned in the chapter first.

The rules on procedural checks apply only to data intercepted in flight, while data already recorded on media should be secured on the basis of provisions on search and detention. It is easy to forget that this also includes "collected" and stored on the email medium. That's what it says.

Article 236a in fine kpk (to the extent it concerns electronic correspondence). This is technically justified. With the exception of transmission times, data consisting of the content of messages sent are generally not at the disposal of telecommunications service providers or network management, and cannot therefore be ‘listened’ 5.

Chapter provisions 26 kpk applies e.g. when needed to intercept e-mail messages during data transfer, "live" 6 .

The question of the acquisition of electronic correspondence on the basis of the provisions on the detention of items and searches raises sometimes incorrect doubts in literature, which will be discussed further in this Chapter in the context of requests for data from processors.

The implementation of the court’s order to actually apply a ‘passive’ procedural eavesdrop requires law enforcement to interact with the relevant communication service provider.

The obligation to cooperate on the part of suppliers results, among others, from Article 237(5) telecommunication operators, including Internet network providers, are also required on the basis of Article 179(3) Telecommunications rights[7] to provide technical and organisational conditions for the access and preservation of telecommunications communications transmitted or received by the end-user or telecommunications terminal equipment by authorised entities (including the Police).

The use of a legal eavesdropping of Internet communications faces many technical problems today and is not as effective as in the past. There is a gap between the scope of legally acceptable access to communication content and the real possibility of obtaining it.

This is because messages exchanged between users (digital data packages) are generally cryptographically protected and encrypted and read on end devices (donors and recipients). Thus, using passive eavesdropping, it is possible to obtain information about the fact that such data are transmitted, e.g.

in the form of billing data, but not about their content. Any data consisting of the information exchanged (e.g. for an incriminating conversation) does not exist in unencrypted form anywhere outside the end devices of the sender and the recipient[8] .

External entities, including telecommunications service providers, are not in possession of cryptographic keys to decipher the data – only the recipient and the sender of the message have them. Thus, using the so-called passive eavesdropping, real access to message content is increasingly impossible.

A further obstacle to be expected is the strong breakdown and independence of service providers. Telecommunications service providers and providers of various electronic services generally function completely independently of each other. The telecommunications service provider (i.e.

data transmission services) with whom the eavesdropping law enforcement authorities cooperate does not need to have real access to the content of encrypted messages.

However, if the content of the message is then stored on the server of the Internet service provider (and this may be the case, for example, with respect to e-mail messages or some text messaging devices), the proper way of obtaining it will be not to e-mail but to obtain data already in the storage phase, using other legal tools.

These problems make the use of "classical" procedural eavesdropping in cases requiring access to Internet-communicated content significantly impeded, unless potentially useless.

Provision Article 241 kpk, however, operates on a two-way basis: it enables both the recording of communication by technical means and the recording of communication by technical means. In practice, this means a statutory authorisation for law enforcement authorities to use all kinds of effective eavesdropping devices and techniques[9] .

This translates into the possibility of using the so-called active eavesdropping, which does not have to be limited to "passive" interception of communication sent through external entities. Active eavesdropping may consist, for example, of installing a data interceptor software in the terminal device to be ‘tipped’.

This generally requires malicious software to be installed in the terminal device by physical access to it or remotely, using appropriate hacking techniques[10].

At present, the rules seem to allow such action to be permitted if an important order is given by the court to initiate a procedural wiretap[11]. The hearing may be carried out using any available forensic techniques to “listen to conversations” (both live and telephone or Internet communications).

However, when installing spyware on the computer of a person whose control is being carried out to ensure that this is in line with the purpose of the operation, it should be limited to capturing communication content.

It would be unacceptable to use such a legal basis to conduct an out-of-the-art ‘remote search’ and to read other data already present in the IT system.

Given how serious interference in the privacy and security of individuals is with the use of such offensive techniques of active process control, it appears appropriate to raise the call for a legislative amendment to the introduction of laws and regulations explicitly providing for the possibility of active electronic e-surveillance using all available techniques for this purpose, but taking into account additional guarantees for the protection of the rights of individuals.

2.2.4. Issue of data

There are many situations in which law enforcement authorities, in order to obtain evidenceable data, rely on a person having access to them to issue them.

Such a decision may be taken whenever the desired content in digital form is at the disposal of the parties third: Electronic service providers (both from Poland and abroad)[12], but also individual individuals (e.g. witnesses).

The content request often concerns those placed on social media, internal data processing systems, online sales platforms or portals offering various services (including e-mail services).

In case of the need to access data processed outside the Polish jurisdiction, the direct protection of data by Polish officers is not possible for legal reasons.

Given the technological reality as well as the principles of procedural economics, proportionality and moderation in searching and stopping things, searching for and securing fragments of data processed on servers of businesses providing electronic services (even those based in Poland) is not appropriate.

However, evidence by issuing it can be obtained by applying several legal bases, depending on the specific circumstances and type of data subject. Under the provisions of the Code of Criminal Procedure, in particular, it is worth considering and delimiting the rules of application Article 217(218) kpk.

2.2.4.1. Release of data in mode Article 217 kpk

It is clear that physical data carriers can be obtained from Article 217 kpk from their authorising officer by means of a call for voluntary issue. Once the data media (as things) are stopped, they can then be examined for digital content.

The analysis of the rules indicates that the data itself can be secured on the basis of Article 217 in conjunction with Article 236a kpk. In this case there may be a specific dissonance resulting from a strong relationship between the carrier (thing) and the data.

Theoretically, it is possible to call on the authorising officer to issue ‘the same’ data on the basis of Article 217 in conjunction with Article 236a kpk. Of course, it is not physically possible to publish the "same" digital data – they must be placed on the appropriate medium to allow their actual transmission.

It is therefore necessary to make copies of the data thus released. It should be critical to assess the situation in which the person concerned is the result of the proceedings, in particular if there is a legitimate suspicion of the offence, he himself shall carry out and issue a copy of his or her data to law enforcement authorities.

From the point of view of the objective of maintaining the full reliability of the material transmitted, if the data is requested in the mode Article 217 in conjunction with Article 236a kpk, data should be copied through direct law enforcement activities using adequate forensic computing tools.

In practice, such actions are abandoned, especially as regards operators third, in principle not interested in the conduct of proceedings and in possession of data to which the appropriate procedure resulting from the application is not obtained Article 237 in conjunction with Article 241 kpk or the manner indicated under Article 218 kpk.

It is worth mentioning that in the case of businesses providing electronic services as separate or complementary (in relation to Article 217 (kpk) the legal basis for the request to issue the data is sometimes indicated Article 18(6) require service providers to make freely available to the competent authorities the data for which they are authorised under that provision. It is therefore, in particular, the personal data of users of services (defined under Article 18(1) sedition), as well as the indicated under Article 18(5) data characterizing the use of the service (so-called operational data, covering multiple metadata of the use of such services, which sometimes allow the user to be identified).

An important part of the current wording Article 18(6) It is not so much an obligation to provide the data indicated (which would be mandatory on the basis of Article 217 in conjunction with Article 236a kpk), how much the obligation of the entities referred to in the Act to provide such data free of charge.

This issue has been disputed in the past, although under the current legal framework it seems to have been resolved[13]. The legal basis for such a request should therefore be Article 217 in conjunction with Article 236a kpk and in conjunction with Article 18(6) I will.

Data from electronic service providers are generally transmitted in printouts or on optical media in text files. The possibility of technical-criminalistic verification of their veracity is then significantly limited.

2.2.4.2. Release and data protection in mode Article 218(218a) kpk

Digital data collection is also possible based on Article 218 kpk and the request for their temporary security for later use allows Article 218a kpk. Both provisions were introduced to bring Polish law into line with requirements Article 16(17) Cybercrime Convention[14], and their current wording was established by a law amending the Code of Criminal Procedure In 2009.[15]

Provision Article 218 kpk allows the authorities, institutions and entities active in the field of mail or telecommunications, customs and tax offices and transport institutions and undertakings to be contacted for correspondence, shipments and telecommunications data.

In the context of only digital evidence, the most important is the possibility of obtaining telecommunications data on this basis. The scope of the term ‘telecommunication operators’ covers telecommunications undertakings within the meaning of Article 2(27) Telecommunications rights[16].

Consequently, the entity scope of the provision does not cover providers of electronic services (which are regulated by the Electronic Services Act). However, in practice, criminal proceedings are constantly confused and the legal basis for demanding the issue of data processed by them – as a rule, exchanged or combined.

This problematic issue will be raised and further developed in this section.

Formally, a request for the issue of telecommunications data on the basis of Article 218 kpk must take the form of a court order or prosecutor indicating the extent of the desired data. This right is conditional on their ‘meaning for the ongoing procedure’.

The text of the provision must be served on the addressees of correspondence and on the subscriber whose list of mergers or other communications has been issued, although the service may be deferred for the time required for the sake of the good of the case, no longer than until the final completion of the procedure (Article 218(2) kpk).

Scope of the request to be formulated on the basis of Article 218 kpk includes ‘correspondence and consignments’, but also does not have such a specific character under Article 180c and Article 180d Telecommunications rights (i.e.

by further internal reference: data specified under Article 159(1)(1) and 3–5, Article 161 and Article 179(9) the same law).

In principle, therefore, access to ‘technical’ data on telecommunications services It is therefore essentially about access to ‘technical’ data on telecommunications connections related to telecommunications services. These may be data on both Internet and telephone calls, coming from large but also small and local service providers.

It is possible to obtain data about the network traffic of users, the fact that they make connections or attempts to connect – both telephone and internet (this is the so-called telecommunications data). This information may allow the identification of users or terminal equipment connected to the network and its geographical location.

Of course, it is possible and often useful to check the reverse – i.e. identification of personal data of the subscriber of the service on the basis of already known law enforcement authorities (e.g.

obtained from the internet service provider in the discussed mode Article 217 in conjunction with Article 236a kpk and in conjunction with Article 18(6) (s) login and connection data from a specific IP number within a specified time. Data available in mode Article 218 kpk does not include the content of data and messages sent.

This is clearly due to the omission of the possibility of requesting the issue of the data in question under Article 159(1)(2) Telecommunications rights (i.e. the content of individual messages).

From the technical side of the demand-based action Article 218 kpk is always implemented directly by telecommunication operators with the relevant data. The manner in which they are carried out is determined by the Regulation of the Minister of Justice[17] issued on the basis of a delegation concluded under Article 218b kpk.

The Regulation is intended, inter alia, to determine the technical arrangements for the preparation of the information systems and networks for the collection of the data in question under Article 218(1) kpk, which does not constitute the content of a telephone conversation or other communication of information, as well as the way in which information is stored in devices containing this data and in systems and on information media, in order to protect such data from loss, distortion or unauthorised disclosure.

However, the content of the implementing rules is not extended: it requires the security of the data by the person authorised by the obliged entity, using technical means enabling them to be subsequently reproduced, and the identification of the case signature, the personal data of the person responsible for carrying out the activity and the time of the security.

Such telecommunications data shall be transmitted to law enforcement in the form of a printout or a digital data medium.

Taking into account the adopted definition of digital evidence, the billing data so transmitted are evidence of digital sense of the largo – they are content of digital origin (from internal data processing systems), but they will be assessed rather than technical reliability.

Such materials are considered to be reliable by the mere fact that they have been provided by the cooperating entity.

It will, of course, be possible to obtain telecommunications data only until the time they are stored. Traffic data indicated under Article 180c Telecommunications rights are held only by 12 months (Article 180a Act).

This retention period results directly from implementation Directive 2006/24 dated 15 March 2006[18] and is not possible and the telecommunications data are destroyed at the end.

However, it should be remembered that there are many other types of data processed by telecommunication and electronic service providers whose retention period does not cover, which may mean both longer and shorter storage.

Lists of calls (e.g. phone billings or metadata about Internet connections) can be obtained through process based Article 218 kpk or outside the process by means of operational and investigative activities.

Due to the rules on the costs of issuing such data (the cost of issuing the data in a procedural manner is borne by the investigating authority) it may sometimes be beneficial to use the non-process mode, although, in principle, it should not be unduly based on non-trial activities in criminal proceedings where this is not necessary[19].

As already mentioned, the recipe Article 218 kpk also allows to request “correspondence and shipments”. With regard to physical letters or packages, its meaning seems obvious. Their release to the court or prosecutor is also subject to additional guarantees.

After first, only the court or prosecutor have the right to open them, though they can also order their opening (Article 218(1) in fine kpk). After second, if it is found that they are not relevant for criminal proceedings, they should be returned immediately to the competent parties (Article 218(3) kpk).

This reservation does not apply to telecommunications data, which, given the technical realities involved, is the right solution. However, the question of the possibility of obtaining digital evidence is important in terms of obtaining digital evidence. Article 218 kpk electronic correspondence.

After all, all types of ‘correspondence and consignment’ are clearly covered by the content that can be obtained in this mode, and Article 236a kpk expressis verbis indicates that the provisions of the whole chapter can be properly applied 25 kpk also to ‘electronic correspondence’.

In fact, it is reasonable to ask whether on the basis of Article 218 kpk (or Article 218 in conjunction with Article 236a kpk) is it possible to effectively request the release of email content stored on servers?

Sometimes a position is expressed according to which the release of electronic correspondence content in mode Article 218 kpk, although already stored "statically" on the servers of the service provider, is unacceptable due to the secrecy of communication, which has its source in both the Polish Constitution and the Telecommunications Law[20].

Consequently, in order to obtain data on the content of electronic correspondence, it would be necessary to apply Article 237 in conjunction with Article 241 kpk (other related data, e.g.

IP number of sender or recipient, are still possible, in the light of this position, to obtain as technical telecommunications data based on Article 218 kpk).

This view is de lege lat unfit[21]. After first, data related to any real-time communication (including email) can only be obtained in the mode Article 237 in conjunction with Article 241 kpk.

Chapter provisions 26 However, kpk does not apply to the content of communication already sent and only stored – whether by their broadcaster, receiver or external entity.

Therefore, if the content of communication is stored, whether in digital form or in the form of printouts or on any other physical medium, it may be the subject of a chapter. 25 kpk.

After second, the content of electronic correspondence is not covered by the public telecommunication secret.

This is not entirely obvious, given that "the content of individual communications" is obviously covered by communication secrecy on the basis of Article 159(1)(2) Telecommunications rights[22] and has been explicitly excluded from the scope of telecommunications data that can be obtained using Article 218 kpk, which results a contrario from the provisions of Telecommunications Law listed therein.

However, the term ‘communication’ is defined under Article 2(17) Telecommunications rights as any information exchanged or transmitted between specific users through publicly available telecommunications services (but does not include radio and television broadcasts due to their public nature).

There is also no limit to what may be the subject of the communication, who may be its broadcaster or receiver, or what form it may be. The concept of a secret message is therefore very broad, referenceable to both voice and data transmission[23].

It is also true that, under criminal proceedings, the content of the individual communications in question under Article 159(1)(2) Telecommunications laws can be obtained through a process wire.

However, unlike telephone communications, the widely understood e-mail service is the so-called hybrid service and actually consists of it two completely separate services: ‘e-mail making available’ (provided by an Internet service provider) and ‘mail forwarding’ (implemented by a telecommunications entrepreneur).

While sending e-mail is a telecommunications service, already the mail service, understood as managing, storing and sharing e-mail resources (e.g. running an online e-mail box), is, according to Directive 2002/21/EC[24], and Directive 2002/58/EC[25] – Information society services and not covered by telecommunications services[26].

It is therefore not appropriate to invoke the obligation of telecommunications secrecy with regard to the content stored on e-mail servers.[27].

It is also evident that the obligation to keep a certain secret under Article 159(1) and 2 Telecommunications rights and the resulting prohibition on the processing of communications content concerns telecommunications operators, not any person processing the content of correspondence sent through telecommunications services.

Operators offering an e-mail service (not its transmission) do so on the basis of the Act on the provision of electronic services, not Telecommunications Laws, and may (although they do not have to) store on their servers copies of messages the content of which may be made available to law enforcement authorities.

Of course, what is worth reemphasizing: this does not apply to the content of live communication, for interception of which can be based on procedural control regulations.

From the above considerations, the essence of the problem arises: a directory of entities required to provide data based on Article 218 kpk does not cover electronic service providers. A broader interpretation of the term ‘postage or telecommunications operators’ is made to include electronic service providers (e.g. e-mail service providers or providers of other e-communications) and is unacceptable.

However, there are no rules that would establish a “secretary of electronic services” in a manner similar to telecommunications secrecy. This increases the capacity of law enforcement, although it seems to be contrary to constitutional standards. It is therefore necessary to consider a change in the current, non-uniform state of law.

While considering the secrecy of communication and its importance for the transmission of data at the disposal of the telecommunications entrepreneur, it is worth noting that Article 218 kpk repeals the communication secret on the principle of lex specialis derogat legi generali.

Therefore, it does not seem necessary to "additional" the avoidance of secrecy, e.g. by recalling Article 180 the legal basis for the provisions in this respect.

On the basis of the existing rules, it should be assumed that email correspondence, as well as any other messages sent via Internet instant messaging or content published on social platforms, can be sought from providers of these services on the basis of the general rule already discussed.

Article 217 in conjunction with Article 236a kpk (for data) or itself Article 217 kpk (in the field of physical media) – if only such data are actually stored and if the entity falls under the Polish jurisdiction. Then the data is a potential factual evidence.

The request for completion is justified Article 218 kpk about formulations of conclusive doubts in the above area (e.g. by adding electronic service providers to the circle required to issue data under this provision).

It is also appropriate to point out that, while the current rules allow fairly free access by law enforcement authorities to the content of electronic correspondence, the absence of a telecommunications secret equivalent should be critically assessed.[28].

The only explanation of such a legal situation seems to be a deliberate legislative omission, ensuring greater efficiency for law enforcement authorities – but at the expense of constitutionally protected individuals' rights.

Telecommunications law, although not applicable to electronic correspondence, applies fully to telephone and SMS content. For practical reasons it is worth to refer here to a possible question about the possibility of obtaining from the telecommunications operator post factum the content of text messages already sent (or even telephone calls). This issue is not free from misunderstandings and wrong expectations of the participants.

It is interesting that some recommend that the party, within the framework of its evidence initiative, request that the [telephone operator] should "require the [telephone] operator to provide text messages which are encrypted on its servers"[29]. This remark was made by the quoted author in the context of civil procedure, although it could be equally appropriate in criminal proceedings. However, such a recommendation should be considered fundamentalally incorrect.

Of course, it is not difficult to imagine the benefits that could arise from the unfettered access of law enforcement authorities to content sent in the past by SMS (although stored by 12-monthly retention period).

However, it is worth recalling that text messages are covered by a telecommunications secret, which results directly from the sound Article 159(1)(2) Telecommunications laws.

The consultation, but also the preservation, storage, transmission or other use of the content of individual messages is prohibited (Article 159(2) the same law) – except where: this is the subject of a service or is necessary to perform it, it shall be with the consent of the consignor or recipient concerned, or is necessary for other reasons provided for by the law.

Telecommunications operators are also obliged to carry out data retention activities in a way that does not reveal the content of telecommunications communications (Article 180a(6) Telecommunications rights).

In fact, the content of messages (SMSs or telephone calls) is "processed" by the operator at the time of their transmission. This is a necessary and therefore acceptable part of the service provided. Later, in principle, this is not allowed. Text messages sent are later only available through terminal devices (e.g.

telephones) of the sender and the recipient of the message (if they have chosen to keep them). Of course, there is a record of the fact that the message is sent in the connection list available from the operator, but not its content.

This can, of course, be secured by the operator in the event of a procedural or operational wiretap, but only from the moment indicated in the relevant provision.

In other words, assuming that telecommunications operators carry out their duties fairly, there is neither legal nor actual possibility of access to text messages sent in the past in a period not covered by the provision on controlling and perpetuating conversations or correspondence.

Final attention should be given to the issue of "data protection" in the mode Article 218a kpk, which enables the authorities, institutions and entities operating telecommunications to be obliged to secure IT data without delay.

Data security may be requested for a limited period of time in the order of the court or prosecutor, no longer than 90 days. In the recipe Article 218a(1) in fine kpk there is also a legislative error in the form of a reference to Article 218(2) dd.

second kpk, indicating the possibility of postponement of service for a specified period of time, no longer than until the final termination of the procedure, but without indicating the person to whom it should be served.

A reasonable view has therefore been drawn up that the provision to secure by analogy to Article 218 kpk shall be served on the data subject[30]. However, it is indicated that the provision Article 218a kpk is in practice not used.

The use of the data protection mode described above is without practical value, since it is possible to simply request data. Prior directing of the provision to secure them seems unnecessary, although it could apply to large sets of data, in which the scope would then be specified in a process useful.

  1. 2.5. Obtaining data processed outside the jurisdiction of the Republic of Poland

Depending on the facts of the matter, different legal tools described so far can be used to gain access to digital content, provided that the device in which the data are processed is located in the territory of the Republic of Poland and the competent person is directly governed by relevant national law, but many of the most popular electronic services are provided by foreign entities. Apart from the jurisdiction of Polish law enforcement authorities, both their headquarters and physical data processing centres are numerous, which forces the use of legal assistance or makes the outcome of the proceedings subject to voluntary issuing, subjecting the effectiveness of law enforcement authorities to the internal rules of the Internet service provider[31].

Of course, jurisdictional problems affect all kinds of evidence. However, in the case of digital evidence, they are particularly common and clearly visible. For many years there has been a problem of national jurisdiction in computer crime in general.

A characteristic feature of prohibited acts using the Internet is their multi-locality – the existence of negative effects of the perpetrator in many geographical areas in such a way that the Codexed perception of the "place of the crime" resulting, in particular, from Article 5(6) kk, is not always adequate and does not always provide stable assessment criteria[32].

For example, the perpetrator of the fraud, the victim of which is a Polish citizen, may operate from the territory of any other country and digital data may be present on servers located in (sometimes many) countries. third.

This is the essence of the cross-border nature of many computer offences, directly affecting the ability to collect digital evidence. The acts of international law that have already been discussed are used for the legal prevention of jurisdictional problems in connection with the cross-borderity of computer crime.

Solutions aimed at harmonising the rules on the prosecution of such offences in different countries are constantly being improved, in particular in the European Union.

A good example of this is accepted In April 2019 Directive 2019/713 on combating counterfeiting and fraud related to non-cash means of payment (replacing the Council Framework Decision Directive 2001/413/JHA)[33].

In particular, the problem concerns data obtained from the operators of popular social networks, online sales and advertising platforms, providing email and electronic communications services, and access to any other data stored on foreign servers as part of cloud data processing services.

The latter concerns the dynamic development of the services sector.

Remote access to IT resources as a service paid on an ongoing basis (or free of charge)[34]) and available from anywhere in the world, facilitates the use (and significantly reduces its costs) of resources such as: computing power, storage space and specialized software[35].

It is sometimes presented through cloud computing, especially by IT leaders using the marketing potential of this slogan, as “another motor, fourth Industrial-technology revolution of humanity”[36].

However, this means that digital materials related to user activity are often placed on media located at a long geographical distance and have only remote access to them. The lack of legal possibility to extend the search to resources available in such a way from the initially examined IT system makes it necessary to seek other solutions.

The concept of cloud computing itself is basically another popular term used to better promote this type of service and obviously has nothing to do with cloud. It is worth pointing out that this popular Polish-language equivalent of the English term cloud computing can be misleading, especially given its common understanding.

This is not about offering “calculation” services in the common sense of the word (or at least not exclusively). By providing cloud services, however, the processing of digital data on remote devices, "invisible" from the perspective of the end user and constituting a metaphorical "cloud" towards its device, is widely understood.

Of course, the solutions are fully real, physical servers and computing centers, located in specific locations and subject to specific organisational authority and jurisdiction.

However, there is a difficulty in discussing cloud issues in the context of the process of obtaining digital evidence, as well as in any other legal context, due to the lack of definitions of such legal services in European legal order.[37].

Looking for a definition of the concept of cloud, you can use the one proposed by the American National Standardisation Institute (NIST) In 2011.[38]: cloud is a data processing model that allows convenient, on-demand access to a shared pool of configurable IT resources (e.g.

networks, servers, memories, applications and services) that can be immediately allocated and made available via a network with minimal management effort and minimum level of intervention of service providers' representatives[39].

However, according to Directive 2016/1148 dated 6 July 2016[40] the concept of cloud data processing includes digital access services to a scalable and flexible set of computer resources for shared use. Regardless of the definitions adopted, it is an activity of making information resources available to users via the Internet.

There are many types of services of this type and detailed ways of providing them[41].

There are many legal and practical problems in obtaining data processed by cloud service providers for the purposes of criminal proceedings. The nature of technological solutions used means that fragments of data related to the same procedure can be found simultaneously in many different geographical latitudes[42].

The high degree of virtualization and geographical dispersal of servers (even belonging to the same entity) in many countries, and thus the lack of physical access to the data storage site or even the lack of knowledge of where they are actually stored, clearly makes it difficult to secure evidence.

The degree of complexity of the technical data processing infrastructure by foreign entities or the number of countries in which the relevant data may be located affect the scale of the difficulties of the evidence.

The formal obtaining for the purposes of criminal proceedings of data processed abroad of the Polish Republic requires, in principle, the application of instruments of international legal assistance. At the same time, the existing international legal aid solutions are far from sufficient.

2.2.5.1. European Investigation Order

In the European Union, legal opportunities for obtaining foreign evidence are relatively simplified thanks to Directive 2014/41 on the European Investigation Order[43], implemented in Polish legal order Act dated 10 January 2018[44] introducing Article 589w-589zt kpk (Chapter 62d kpk). The END Directive has largely replaced the application of the European Convention on Criminal Assistance between Member States of the European Union[45], facilitate the security and collection of evidence, including digital origin.

European Investigation Order (END), in accordance with Article 1(1) the END Directive, is a judicial decision issued or approved by the judicial authority of the Member State (issuer) for the purpose of calling on another Member State (executor) to carry out one or several specific investigative activities to obtain evidence.

The issuing authority may also be the prosecutor. If, on the other hand, the action is reserved to a decision of a court, the issuing of an EIO is also a matter of its competence (e.g. a procedural eavesdrop order).

The regulations contained in the END Directive allow for initiatives to be taken to request evidence from persons directly involved in the criminal proceedings.

This favourable solution is subject to significant restrictions in the light of national rules – the applicable rules of procedure of the general office of the prosecutor's office do not provide for the possibility of requesting foreign legal assistance from district prosecutors without the involvement of the superior units[46].

It is justified to amend the internal rules in this respect in such a way as to allow the actual and rapid use of the described tool directly by those familiar with the facts of the case – without unnecessary extension of the existing business path.

The advantage of the END compared to its ‘previous’ European evidence order introduced earlier by the Council Framework Decision Directive 2008/978/JHA[47], is the extension of its scope. Earlier solutions only allowed evidence already held by the authorities of the executing State to be requested.

It was therefore possible to request, for example, a report of the examinations carried out, but no longer to carry out them[48]. It is now also possible to determine which investigative activities are to be carried out and to call on the authorities of a foreign State to perform them.

The advantage of the END is also that it is not limited to the activities specifically identified – on the basis of it it can be requested, among other things, for the procedural protection of digital data contained in devices in the territory of the executing State.

The whole procedure may, unfortunately, be relatively time-consuming: the decision to implement the EIO should be issued in the executing State during the 30 the days following receipt of it and the duration of the operation may be up to 90 the days following that provision. In total, this refers to the implementation time up to 120 days – in the case of multiple computer offences, this may result in a non-returnable loss of evidence or the impossibility of effectively establishing or prosecuting the perpetrator[49].

In view of this, among others, additional special solutions are being developed.

The European Commission's legislative proposal procedure is also ongoing during the preparation of this text dated 17 April 2018 on the adoption of a Regulation of the European Parliament and of the Council on a European order for the issue of electronic evidence[50] evidence in criminal matters and European order to secure evidence on electronic evidence in criminal matters[51].

The proposed regulation aims at adapting the mechanisms for cooperation between EU countries to the digital era, making available judicial tools and law enforcement that take into account modern forms of both communication between criminals and ways of combating them.

The essential element of the proposed Regulation is the introduction of a European order for the issuing of evidence and a European order for the freezing of evidence (issued or approved by a judicial authority of a Member State).

They are not intended to replace the instruments available under the END Directive, but to provide additional tools to law enforcement authorities and are in fact similar to those in Poland with Article 218(218a) kpk (introduced to bring the rules into line with the requirements of the Convention on Cybercrime, with which EU legislation is also to be harmonised).

On the basis of such orders, it should be possible to oblige a service provider located in another jurisdiction to issue the necessary evidence or to secure it.

A great advantage of the designed tools is the possibility to direct these orders to providers (electronic communications service providers, social networking sites, trading platforms, Internet infrastructure providers and other entities).

The adoption of these rules in the form of a Union regulation will allow for direct application of them, which will benefit from the uniformity of the solutions applied.

2.2.5.2. Transmission of data outside the European Union

In dealing with countries outside the European Union, despite the widespread awareness of the existence of this problem, there is not a sufficiently efficient and efficient evidence collection system. For digital data processed by global IT industry entities, this lack is particularly severe.

In principle, digital security, like any other evidence, may be based on the application of Mutual Legal Assistance Treatments (MLAT).

This cooperation model is based on the idea of mutual respect for the rights set out in the agreements, particularly between the European Union and the countries third (for example with the United States or Japan)[52]. This type of procedure involves indirect obtaining a legally effective evidence order in a foreign country[53].

Such a system is highly inefficient, especially in computer crime cases.

In the case of requests to the United States, where, due to the location of the headquarters of many key data processors, the highest number of requests is received, the waiting period for response is from 8 to 15 months – without guarantee that the data will be transmitted[54].

Applications prepared by the Office of International Cooperation at the National Prosecutor's Office shall be forwarded to the US Department of Justice through the Polish Ministry of Justice and only then can they be officially transmitted to the specific data processor.

The Cybercrime Convention, now a fundamental multilateral framework for combating computer crime[55], in its current form, it also does not solve most procedural problems related to the request for data from foreign entities.

The solutions proposed in the Convention generally boil down to the requirement that States Parties introduce legal aid instruments and procedures allowing access to digital evidence. In particular, it was pointed out the need to introduce evidence warrants to enable the issue but also to secure the data.

The provisions of the Convention are mandatory, and in the Polish procedure their implementation was to constitute appropriate Article 218(218a) kpk. Their reflection under EU legislation is the solutions planned in the Electronic Evidence Regulation.

However, from the point of view of applying the Convention on Cybercrime, it is a serious problem to direct evidence orders to service providers outside the territory of the Parties to the Convention. A gradual change in this situation may be due to the proposal for adoption currently under preparation.

second Additional Protocol to the Convention on Cybercrime[56]. The aim of the proposed solutions is to improve cross-border access to digital evidence, with a particular focus on data processing in cloud computing[57].

Results of an international survey conducted among representatives of investigative practice[58] point to the existence of many additional problems related to the international exchange of information on digital evidence. one There is a lack of international standardisation of forms for such applications – in most applications for legal assistance are formulated on the basis of national standards for their preparation, resulting from local rules, hampering their priority and implementation.

Given these factual, technological and legal circumstances, the possibility of formally obtaining evidence processed outside the jurisdiction of law enforcement is very limited. Today, de facto states do not have any supervision over the processing of binary data or supervision is increasingly illusory[59].

Formal difficulties and a long period of implementation of applications for international legal assistance prejudge the ineffectiveness of criminal proceedings in many cases. In the near future, therefore, new, modernised international agreements on legal assistance for the prosecution of computer crime will be absolutely necessary.

Action in this direction is already being taken in various international fora. As far as the European Union is concerned, they are not only in attempts to improve existing institutions (e.g. the EDP), but also in the perception of the need for concrete action to address jurisdictional and enforcement problems in cyberspace.[60].

In the position expressed in the resolution of the European Parliament of 3 October 2017[61] it is right to stress that the current fragmented legal framework can create difficulties for service providers who seek to comply with the demands of law enforcement.

There is a cautious hope that the planned adoption of the Electronic Evidence Regulation, unless it solves any existing problems, will improve the functioning of the justice system in the field of cross-border digital evidence collection in the European Union.

Work on second Additional Protocol to the Convention on Cybercrime, although the current stage of work is too early to assess future solutions.

The correct course of action is to debate the fight against cybercrime more effectively, an important element of which is the adoption of efficient and relatively universal evidence procedures, including in the global dimension.

__________________________________

[1] S. Waltos, Criminal Trial. System outline, LexisNexis, Warsaw 2008, p. 377, 379.

[2] Cf. Supreme Court resolution of 21 March 2000, reference no. I KZP 60/99, Judgment of the Supreme Court Criminal Chamber and Military Chamber 2000, No 3–4, item 26. Cf. P. Kosmaty, Hearing the Trial – a dying institution for the fight against crime, “Prosecution” 2009, No 2, p. 16

[3] I. Dembowska, Use of materials collected during the application of operational and procedural control of conversations (postulates de lege lata), Faculty of Law, Administration and Economics of the University of Wrocław, http://www.bibliotekacyfrowa.pl/Content/58879/02_Izabela_Dembowska.pdf, access 19 June 2020

[4] VoIP, Voice over Internet Protocol, consists in converting the content of the conversation to digital data, and then transferring it through the information network between the callers.

[5] D. Świecki (ed.), Code of Criminal Procedure, Wolters Kluwer Polska, p. 877

[6] L. Paprzycki (ed.), J. Grajewski, S. Steinborn, Comment updated to Article 424 Code of Criminal Procedure, LEX 2015.

[7] Act dated 16 July 2004 – Telecommunications law (Journal of Laws of 2019, item 2460 as amended).

[8] Encrypting and decrypting messages on terminal devices through network communication programs becomes a modern standard and is used by many popular providers (they are offered by programs such as WhatsApp or Signal). Although this solution does not guarantee the security of communication in every situation, it is a very strong tool for protecting privacy. see L. Newman, Encrypted mesaging isn’t magic, Wired from 14 June 2018, https://www.wired.com/story/encrypted-messaging-isnt-magic/, access 19 June 2020

[9] S. Waltos, Criminal Trial. System outline, Warsaw 2003, p. 368.

[10] P. Necessary, 3 ways to eavesdrop a mobile phone... and advice on eavesdropping avoid, “Danger” with 26 October 2013, https://niebezpiecznik.pl/post/3-sposoby-na-podsluch-telefonu-komorkowego/, access 19 June 2020

[11] A. Kiedrowicz, The question of control of communications in the framework of Internet telephony, “Prosecution and Law” 2008, No 10, p. 130; A. Lach, Electronic Evidence... p. 74; M. Szachnitowski, Electronic Evidence in Criminal Procedure, in: P. Czarnecki, M. Czerwińska (ed.), Catalog..., p. 200

[12] A. Lach, Fighting illegal content on the Internet, Toruń 2015, p. 15.

[13] In the previous state of the law to the cost of developing data made available on the basis of Article 18(6) use Article 619(1) in conjunction with Article 618(1) kpk (cf. Supreme Court resolution from 30 September 2014, reference no. I KZP 18/14, Supreme Court Judgment Base).

[14] L. Paprzycki (ed.), J. Grajewski, S. Steinborn, Comment..., comment on Article 218 kpk.

[15] Act dated 24 April 2009 amending the Act – Telecommunications Law and some other laws (Journal of Laws of 2009, item 716)

[16] 5 The telecommunications business register is kept by the Electronic Communications Office and available online: https://bip.uke.gov.pl/rpt/, access 19 June 2020

[17] Regulation of the Minister of Justice dated 28 April 2004 on the technical arrangements for the preparation of information systems and networks, for the collection of lists of telephone calls and communications and for the security of information (Journal of Laws of 2004, item 1023).

[18] Directive 2006/24 dated 15 March 2006 on the retention of data generated or processed in connection with the provision of publicly available electronic communications services or the provision of public communications networks and amending Directive 2002/58

[19] Cf. with A. Lacha's statement quoted in: G. Science, 6th edition of the seminar entitled “Legal Corporate Computer Science” on “Electronic Evidence in Criminal Procedure” (Warsaw, 12 March 2008), „Prosecutor’s Office and Law’ 2008, No 7–8, p. 251.

[20] J. Kudła, A. Staszak, Process and operational control of correspondence stored in the so-called cloud, "Prosecution and Law" 2017, No 7–8, p. 37, 47–49.

[21] Similarly: M. Rogalski, Sharing telecommunications data to courts and prosecutors, “Prosecution and Law” 2015, No 12, p. 65–66; T. Grzegorczyk, Code of Criminal Procedure. Commentary, Kraków 2005, p. 590; J. Skorupka (ed.), Code of Criminal Procedure. Commentary, Warsaw 2016, p. 505–506; A. Lach, Obtaining evidence in the framework of correspondence control in the criminal process, in: B. Opaliński, M. Rogalski (ed.), Correspondence Control. Selected issues, Warsaw 2018, p. 71.

[22] By fulfilling the requirements arising from, inter alia, the Directive 2002/58 and provisions of the Constitution of the Republic of Poland. see W. Wing, Constitution of the Republic of Poland. Commentary, Warsaw 2013, p. 145.

[23] A. Krasuski, Telecommunications Law – comment, Warsaw 2010, p. 601.

[24] Article 2c Directive 2002/21 dated 7 March 2002 on a common regulatory framework for electronic communications networks and services (Framework Directive).

[25] Directive 2002/58 dated 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications).

[26] Resolution of the Supreme Court of 30 September 2014, reference no. I KZP 18/14. Cf. order of the Wrocław District Court from 24 April 2014, reference no. III Kp 307/14, The portal of General Court rulings. (In view of the current wording of the Law on Electronic Services, these rulings are partly obsolete as regards the settlement of the costs of transferring data to law enforcement authorities.)

[27] In addition, it is worth considering that from the sound Article 218 kpk clearly shows the possibility of gaining access to correspondence on the basis of it, so this would, as a matter of fact, repeal the mystery in force in this area (especially in relation to Article 236a (kpk)

[28] A. Lach, Obtaining evidence in the framework of correspondence control in the criminal process, in: B. Opaliński, M. Rogalski (ed.), Correspondence Control. Selected issues, Warsaw 2018, p. 73. Lt. K. Szymielewicz, M. Szumańska, Access of public authority to the data of Internet service users – seven issues and several hypotheses, Warsaw 2013, p. 27

[29] P. Telusewicz, Content of SMS as dubious evidence in the civil process, in: J. Misztal- -Konecka, G. Tylec, Evolution of Polish law under the influence of information technology. Electronic aspects of justice, Lublin 2012, p. 178–180.

[30] M. Siedlecki, Telecommunications data acquisition in preparatory proceedings, in: P. Czarnecki, M. Czerwińska (ed.), Catalog...,

[31] Lt. A. Lach, Combating... p. 15

[32] M. Siwicki, Grounds for determining the jurisdiction of cybercrime under Polish criminal law in the light of international normative standards, “Palestra” 2013, No 3–4, p. 107.

[33] The adoption of the new Directive is directly linked to the development of the digital services market and, as the preamble states, "[n]but it updates and complements the Council Framework Decision Directive 2001/413/JHA to include additional rules on crime, in particular relating to computer forgery, penalties, crime prevention, victim support and cross-border cooperation.’

[34] There are many services of this type provided free of charge: e-mail or remote storage (for example, Google Drive, Dropbox). It is worth remembering that the "freeness" of such services often involves the use of user data and their activity for marketing purposes. This problem concerns social media and any other solutions provided by IT corporations to an even greater extent. The view that ‘real’ users of these services are advertisers rather than individuals is increasingly justified. see Among others, R. McNamee, Zucked: Waking up to the Facebook catastrophe, Penguin Press 2019.

[35] A. Pichan, M. Lazarescu, S. Teng Soh, Cloud forensics: technical challenges, solutions and comparative analysis, "Digital Investigation" 2015, No 13, p. 39.

[36] Microsoft, Cloud computing: social benefits, economic opportunities, regulatory challenges, Presscom 2018, p. 11–19; P. Giraud, How cloud is driving the next industrial revolution, Oracle, https://www.oracle.com/uk/cloud/paas/features/next-industrial-revolution.html, access 19 June 2020

[37] A. Krasuski, Cloud computing. Legal aspects of application, Warsaw 2018, p. 35.

[38] Given the dynamic development of the industry, this was a long time ago. Hence, it is now proposed to update it. see C. Miyachi, What is “cloud”? it is time to update the NIST definition?, “IEEE Cloud Computing” 2018, No 5(3), p. 6–11.

[39] P. Mell, T. Grance, The NIST definition of cloud computing, https://csrc.nist.gov/publications/PubsSPs.html#800-145, access 19 June 2020

[40] Directive 2016/1148 dated 6 July 2016 on measures for a high common level of network and information systems security within the Union.

[41] A detailed description of various technological and organisational variants of cloud services was presented, among others, by A. Krasuski, Cloud...

[42] P. Opietek, Selected... p. 66. Lt. B. Hay, K. Nance, M. Bishop, Storm Cloud Rising: security challenges for IaaS Cloud computing, Procedures of the 2011 44th Hawaii International Conference on System Sciences (HICSS) 2011, p. 1–7.

[43] Directive 2014/41 dated 3 April 2014 on the European Criminal Investigation Order, hereinafter: END Directive. It is worth remembering that Denmark and Ireland do not participate in its application.

[44] Act dated 10 January 2018 amending the Act – Code of Criminal Procedure and some other laws (Journal of Laws of 2018, item 201).

[45] Council Act dated 29 May 2000 establishing, in accordance with Article 34 Treaty on European Union, Convention on Mutual Assistance in Criminal Matters between Member States of the European Union.

[46] Regulation of the Minister of Justice dated 7 April 2016 – Rules of Procedure of the Public Prosecutor's Office (Journal of Laws of 2017, item 1206 as amended), Further: Regulation of the Minister of Justice dated 7 April 2016 – Rules. see provisions of Chapter IV

[47] Council Framework Decision Directive 2008/978/JHA dated 18 December 2008 on the European Evidence Order on the subjects, documents and data to be used in criminal proceedings.

[48] G. Krysztofiuk, European Investigation Order, ‘Prosecution and Law’ 2015, No 12, p. 82–83.

[49] P. Opietek, Selected... p. 70.

[50] The terminology used in international legal and official documents often uses the concept of ‘electronic evidence’, which is not forensically correct.

[51] European Commission proposal from 17 April 2018 concerning Regulation of the European Parliament and of the Council on a European order for the issue of evidence relating to electronic evidence in criminal matters and a European order for the freezing of evidence concerning electronic evidence in criminal matters hereinafter: the Electronic Evidence Regulation, RODE), https://eurlex.europa.eu/legalcontent/PL/TXT/?uri=CELEX%3A52018PC0225, access 19 June 2020, p. 2.

[52] Council Decision Directive 2009/820/CFSP dated 23 October 2009 on the conclusion, on behalf of the European Union, of an extradition agreement between the European Union and the United States of America and of an agreement on mutual legal assistance between the European Union and the United States of America; Council Decision Directive 2010/616 dated 7 October 2010 on the conclusion of the Agreement between the European Union and Japan on mutual legal assistance in criminal matters.

[53] P. Opitek, Clarifying Lawful Overseas Use Data Act – a new digital data collection model in criminal matters, Kościuszko Institute, April 2018, https://ik.org.pl/wp-content/uploads/brief-programowy_clarifying-lawful-overseas-use-data-act.pdf, access 19 June 2020

[54] P. Opietek, Selected... p. 71

[55] This was recognised in the European Union cyber security strategy with 2013: Joint Communication from the Commission and the High Representative of the Union for Foreign Affairs and Security Policy on a European Union cybersecurity strategy: open, secure and protected cyberspaces.

[56] At the time of preparation of this text, a working version of the proposal for the content of this Additional Protocol shall be made available, https://rm.coe.int/t-cy-2018-23-provisional-text-protocol-provisions/1680a00e6e, access 27 October 2020

[57] T. Minárik, Council of Europe Ponders a new treaty on cloud evidence, https://ccdcoe.org/council-europe-ponders-new-treaty-cloud-evidence.html, access 19 June 2020

[58] I. James, P. Gladyshev, A Survey of Mutual Legal Assistance involving digital evidence, "Digital Investigation" 2016, No 18, p. 23–32.

[59] P. Opietek, Selected... p. 68.

[60] European Union Council conclusions on improving criminal justice in cyberspace, ST9579/16, http://www.consilium.europa.eu/pl/press/pressreleases/2016/06/09/criminal-activities-cyberspace/, access 19 June 2020

[61] European Parliament resolution dated 3 October 2017 on the fight against cybercrime, European Parliament resolution (2017/2068 INI)).

The article comes from the book Lewulis Peter, Digital evidence – forensic theory and practice in Polish criminal proceedings, Warsaw University Publishing House, 2021, p. 95-118.

Continue exploring our insights.

View the full archive
Publications

Damage to the consignment in connection with the execution of the contract of carriage of goods. Selected issues

It happens in everyday life that during the execution of a transport contract a consignment is lost or damaged in part or in full.

Publications

Legal effects of a ‘hull’ board in a limited liability company

This article addresses the issue of “hull management” in a limited liability company under Polish law.

Publications

Mutual relations between the buyer's rights arising from the warranty for defects in the goods sold, the quality guarantee and the seller's liability for improper performance

In case of a defect in the goods sold to the buyer, both the warranty rights for defects and the quality guarantee (if the seller provides a guarantee).