In the third, Last, part of the text from the chapter "Digital Evidence – a theory and a criminal practice in Polish criminal proceedings", we have the opportunity to read the author's proposals on changes in the protection of digital evidence or the issue of such data by entities with right of access to them.
2.2.6. Open source materials and voluntary data transmission
In addition to the formalised instruments of international legal assistance, which are too often time-consuming and inefficient, it is worth considering the possibility of establishing direct contact between law enforcement authorities and those with access to evidenceable data.
Direct non-criminal methods of contact can be seen as possible alternative means of obtaining data[1]. This applies both to contacts initiated by law enforcement authorities and to voluntary delivery of content by individuals. third.
However, direct inquiries to online service providers require that they accept that they may refuse voluntary assistance under internal rules, foreign legal standards and their own corporate policy. From the point of view of the Polish criminal procedure, it should also be remembered that this practice is not fully correct.
Process activities should be carried out in accordance with the relevant provisions and legal aid applications should not be replaced by non-trial cooperation. This should be limited to strictly police activities and carried out in the framework of operational and investigative activities rather than for procedural purposes.
Nevertheless, many of the largest providers of electronic services offer law enforcement authorities the opportunity to cooperate directly – more or less formalised.
Examples of such activities are provided by large electronic services industry players. For example, Facebook 2 makes available to law enforcement authorities (not only American) a contact form enabling submission of requests for data on different users[3].
However, aid shall only be granted on a voluntary basis and under conditions laid down in the internal rules of procedure of the entrepreneur in accordance with American law.[4]. The internal procedure for the voluntary transfer of user data also provides for Google.
In this case, state institutions outside the United States are required to show a ‘valid legal document’ (e.g. transfer of a court order) and the request can only be met if it complies with ‘international standards, US law, the laws of the requesting country and Google rules’. 5 .
Despite these apparent facilitations with the presence of Polish[3] law enforcement authorities for voluntary transmission of data by U.S. service providers have many problems arising from the characteristics of their legal system.
After first, for strong protection of freedom of expression (guaranteed first Amendment to the United States Constitution, taken very seriously there) 6 Requests for data on prohibited acts of breaching the freedom of expression (e.g. hate speech) allowed by the Polish Authority are generally not implemented.
After second, due to the principle of opportunism of criminal proceedings, there are not many proposals concerning "too trivial" events. 7 For the standards there. These issues were also highlighted by the American side to representatives of the Polish judiciary during official working meetings[8].
Requests for transmission of user data to US entrepreneurs by Polish law enforcement authorities, regardless of the mode chosen, are generally not fully implemented or even left unanswered. The assessment of the situation is supported by the transparency principle adopted by the main IT service providers.
The analysis of the available information on the number of requests and the extent to which they are taken into account leads to the conclusion that the provision of data processed by Google 9 is expected to occur if one third general inquiries conducted by Poland. Higher, though little, is the effectiveness of the urgent proposals, i.e.
concerning ‘exceptional situations requiring immediate response’ 10 , but the number is much lower.
In practice, relevant evidence of digital origin data is very often obtained from so-called open sources[11]. This can be done both when formal procedural tools or voluntary cooperation with data holders fail, and when they appear unnecessary to use.
It is about using publicly available content, published on the Internet: content of websites or social networks. They are often very important for the proceedings. They are technically processed on service servers – domestic or foreign.
In such situations, access to the content of the data can be exercised directly by law enforcement authorities, and the "general availability" of such information allows to obtain it without using the means of procedural coercion[12].
The general legal basis for such a "crossing" national jurisdiction may provide Article 32 Cybercrime Convention. In theory, however, this only applies to access to open sources made available from the territory of other Parties to the Convention.
Of course, information collected in this way can also be of great importance in operational and research work, both in a preventive and investigative context. Information from open sources may not only in itself constitute evidence, but may also be the basis for establishing another evidence (e.g.
the identity of witnesses or suspects based on the content of their social media profiles). If the analysis of open sources serves to determine further directions of process activities, a sufficient form of documentation appears to be a business note: after all, the appropriate evidence will only be carried out, e.g.
by interviewing a person with personal features on a publicly available website.
However, the strict use of such data is more difficult. This may be the case, for example, when the content on the website itself fills in the hallmarks of a prohibited act (e.g.
when it concerns the content of an entry in the comments section of the portal facebook.com, video published on the website youtube.com or the use on the “private” website of copyright-protected photos).
It is difficult to get acquainted with such material in principle by ‘entering the website’, but it is difficult to bring it into criminal proceedings in the correct procedural manner due to the lack of legal basis applicable to it.
The lack of a clear legal basis for the procedural safeguarding of open-source content creates clearly visible chaos in practice.
Digital content from open sources is introduced into the criminal trial through witness testimony, business notes, annexes to the testimony protocols or on the way (inappropriate – as mentioned earlier) to the website's inspection.
From a forensic point of view, none of these methods guarantee the ability to demonstrate the technical authenticity of such materials, as it does not take into account the possibility of manipulating the displayed content.
The criminal procedure is not known to have specific tools for procedural safeguarding open sources of content, which justifies raising legislative demands in this area.
Finally, it is also worth reminding that even in the case of foreign servers, the users themselves have access to the data processed there – service account distributors: social media users, instant messaging, email accounts, virtual disks storing data in the cloud, etc.
Clearly, the authorised user has access not only to publicly available content, but also to content with limited audiences, including (own) correspondence via Internet instant messaging. It is worth noting that the user of data processed in the cloud is not a ‘disposal’ within the legal or technical meaning.
However, he is a person entitled to access them in the framework of the service provided and may transfer them. The user of the services provided by electronic means does not process and is not in possession of data, and is therefore obliged to issue data (e.g.
in mode Article 217 in conjunction with Article 236a kpk) cannot be considered correct.
In practice, digital content is very often provided by victims or witnesses on their own initiative. In particular, these are evidence of the words of the participant of the proceedings, transmitted in the form of printouts during the notification of the offence (e.g.
printout of the website content conducted by the impostor or printout of the electronic communications content). Cooperation with the victim may also improve and, in certain situations, enable the law enforcement authorities to release data from foreign service providers.
An application for the issue of personal account data directly from the person entitled shall, in principle, be made by the service providers in any case, regardless of the circumstances of the case. The same request from law enforcement authorities is subject to a long-term procedure with uncertain results.
Copies of the event data (conversations, computer screenshots, etc.) are transmitted by victims most often in the form of printouts. The credibility of such material on a criminal basis may be called into question – although this is not often raised or effective in practice.
2.3. Access to data and legally protected secrets
There may be very different content in the information systems and on the media of data disclosed during the process, including sensitive or legally protected data. It is not difficult to imagine that documents, notes or any other information covered one of Polish legal secrets are digital and stored on an electronic medium.
The wide use of electronic communications and files (graphic, text or audiovisual) in the daily work of many professions, including lawyers and lawyers, may have consequences for the admissibility of securing digital evidence. In order to be more transparent, the remaining considerations require separate attention.
The secret may include, in particular, the data on the media disclosed in the course of the search or request for the release of the items – and thus obtained in the mode Article 217(219) either Article 220(3) kpk (ew. in conjunction with Article 236a kpk).
The handling of media of content covered by the secret issued or found in the course of the search shall be governed by the rules of the Article 225 kpk, and in the scope of the information on them only – Article 225 in conjunction with Article 236a kpk.
As a general rule, after receiving a statement that the materials issued or found contain classified information, messages covered by professional secrecy or other legal protection (or of a personal nature), the investigating authority is obliged to transmit such material to the prosecutor or the court without being familiar with it (Article 225(1) kpk).
Such a procedure shall, in fact, only be applied on the basis of a statement by the person whose search is carried out. Hence, the material in the possession of a person suspected of having committed a crime was rightly excluded. It also does not cover ‘restricted’ or ‘confidential’ materials 13 (Article 225(2) kpk).
In contrast, a psychiatric record received or found in the course of the search is subject to rigor (Article 225(4) kpk), although this does not apply when the prosecutor finds or retains such material personally[14].
Where a declaration of the existence of materials covered by a secret relates to the whole of the vehicle concerned, it shall not be permitted to secure such data at the place where the activity is carried out. Copies of the evidence will only be possible outside the search operation and with proper mode.
However, this is indicated for classified information and professional secrets (which exist in the Polish legal order very many 15 ) under Article 226 kpk by internal reference to the appropriate application of prohibitions and restrictions of evidence resulting from Article 178-181 kpk. By their analysis, it should be stated that:
- for the use of digital material containing classified information on the ‘secret’ or ‘closely secret’ clause, it is necessary to release it from secrecy by a qualified authority, as the court or prosecutor may request (Article 179 in conjunction with Article 226 and Article 236a kpk). In particularly justified cases on the basis of Article 57(5) Law on Public Prosecutor's Office 16 , the power to abolish or amend a security classification imposed by another body shall also be granted to the Attorney General, after having consulted the latter authority and informed thereof by the Prime Minister. Of a standard under Article 225(2) kpk shows that the materials retained or found during the search do not apply Article 180(1) kpk as regards the confidentiality of classified information with a ‘reserved’ or ‘confidential’ clause;
- by content Article 178 kpk and the absence of further exclusions in this respect in any situation shall not be exempted from secrecy material relating to circumstances to which the defence secret or confessional secret applies[17]. However, as regards materials covered by additional secrecy, the solutions for its protection are further discussed. Article 225(3) kpk. Relatively, material related to the conduct of mediation proceedings is also heavily protected, unless it concerns information concerning the offences listed under Article 240(1) kk.
The protection of professional secrecy may, in principle, be abolished by a court or prosecutor, taking into account the condition of the good of the judiciary and unless otherwise provided for in specific provisions. Such a decision should take the form of a provision for appeal (Article 180(1) kpk).
However, in the field of materials covered by secrets: notary, barrister, counsellor, tax advisor, physician, journalist 18 , Statistical or secret of the Attorney General, only a court (a decision to be complained about) may grant exemptions, and only if necessary for the sake of justice (Article 180(2) kpk).
The possibility of waiving the professional secrecy of a lawyer and lawyer in any circumstances raises a lot of controversy in the legal profession because of the particular place it occupies in its existing representatives with ethical principles.
Where the protection of materials issued or found in the course of the search is deducted, appropriate use should be made Article 181 in conjunction with Article 226 kpk (and possibly in conjunction with Article 236a kpk). Even in the event of abrogation of secrecy, such materials must be used in court proceedings excluding disclosure.
The manner in which they are stored, made available and relied on in judgments and letters shall be determined by a regulation of the Minister of Justice issued on the basis of a delegation from Article 181(2) kpk[19].
It does not, however, provide for specific solutions in the context of the storage or consultation of digital evidence – depending on the form they should therefore be treated as objects (data carriers) or documents (prints) referred to in that Regulation.
The defense secret is protected in a special way.
If the defender or other person requested to issue the item or to be searched, declares that the material issued or found covers the circumstances associated with the performance of the defence function, the body carrying out the activities shall leave it to the defender without being aware of its content in general (Article 225(3) kpk).
This is a very good solution. After first, It corresponds to – generally accepted and derived from constitutional values – the principles of the criminal process relating to the right of defence (Article 6 (kpk) and the prohibition of evidence resulting from Article 178(1) kpk.
It is worth noting that the defence secret is absolute, and the defender cannot be released from it by anyone and at any time[20]. Moreover, the defence secret is complete and covers all information and circumstances related to the performance of this function.
In the context of digital data, it covers not only the content of digitized documents (copying and draft writings on the case, photocopies of files stored on the computer, etc.) or the content of communication with the client (conducted e.g.
via e-mail), but also any other data related to the conduct of defence, or even the fact of its conduct. The correct conclusion, therefore, is that any digital data related to e.g. the search for information useful for the conduct of the case, telecommunications data, etc. may be covered by the defence secret.
A wide range of protection of defence in criminal proceedings and its inclusion in the context of the material disclosed in the course of the search deserve approval and the resulting restrictions binding law enforcement authorities are necessary in a democratic state.
It is worth noting that the procedural law refers to a statement by a person who is “a defender” – it does not have to be a lawyer or legal counsel, as the provision also applies if the applicant has made such a statement, which is authorised to defend himself[21]. It may also come from a non-defendant (e.g.
a householder or employee of a law firm), though under Article 225(3) dd. second The procedural law provides for a situation where a statement by a non-defendant raises doubts. At that time, the authority carrying out the activities shall transmit the disclosures to the court without being consulted.
In turn the court has the right to read them and return them (in whole or in part) to the person from whom they were taken or to issue a decision to detain them.
The situation may be problematic where the same medium contains, according to a statement by the authorising officer, data covered by a defence secret and other data not protected by it and useful for the conduct. It is then only possible to secure part of the data – if the controller precisely determines which components are protected. If the conditions are met Article 225(3) dd. second The procedural law may be considered as an alternative.
It can be seen that the fact that the data covered by these secrets is stored on a specific medium is in some way an additional circumstance justifying the retention of physical computer equipment (and in any event media that may contain evidence).
In such a case, the procedural authorities should secure the medium without being aware of its contents and should make it available to the competent authority.
In my opinion, by applying Article 236a kpk, it would also be possible to make copies of all data from a vehicle containing protected materials, provided that such action is carried out in a way that effectively prevents the data from being read.
The execution of a forensic copy of the data carrier is basically an automated process as part of the use of appropriate tools, and its verification takes place by comparing checksums rather than browsing data content. This seems acceptable, though not without controversy.
However, it seems incorrect that only copies of files would be made of which the authorising officer does not declare to be covered by secrecy (although in the case of defence secrecy this may be the only legally acceptable way to obtain them).
Apart from the legal controversy regarding this solution, this carries a high risk of misleading law enforcement authorities by a person interested in the outcome of the action[22].
Standards resulting from Article 225 kpk shall apply both to materials disclosed in the course of the search and to those requested on the basis of Article 217 kpk.
The issue of telecommunications secrecy has already been addressed in the course of this Chapter in the context of the use of procedural eavesdropping and the issue of data based on Article 218 kpk.
Resignation requires, however, that in the current state of the law there is no statutory equivalent of the communication secrecy of the existing electronic service providers (e.g. sales service providers, e-mail services or social media providers).
Any data related to these services shall not be protected in a manner similar to the content of ‘traditional’ correspondence or telephone calls.
It should be borne in mind that law enforcement authorities may request the issue of data to any entity. Among them, they may also be obliged to keep the secret regulated in separate provisions.
A good example of this, especially in the era of electronic banking, is the banking secret specified under Article 104 Banking rights 23 , which includes ‘all information’ on banking activities[24].
The popularity of frauds that are carried out through the network makes data from banking transaction services of considerable importance for identifying suspects (even when the bank account was established using another person's data or when the case concerns a breach of the bank account – any login of the actual perpetrator on the transaction site will constitute a digital trace of his activities 25 ).
In cases where exhaustively listed under Article 105 The banking rights of the bank shall transmit the information covered by the secrecy at the request of the court, the prosecutor and other entities mentioned in that provision.
In addition to the situations of disclosure of banking secrecy mentioned therein, the prosecutor conducting the investigation for a criminal offence may request, or fiscal criminal offence, but only on the basis of a decision given in this case by a local court (Article 106b Banking rights).
In addition, it is worth recalling that in connection with the content Article 104(3) The bank rights of the person to whom the banking secret is concerned are his/her agent – may authorise the bank to provide specific information to law enforcement authorities[26].
In practice, these provisions of banking law are indeed important for many online fraud proceedings.
In summary, when carrying out procedural activities aimed at obtaining evidence of digital origin for the purposes of criminal proceedings, attention should be paid to the possibility that they contain protected content.
In the Code of Criminal Procedure, matters relating to public and professional secrets protecting materials issued or found during the search have been fairly detailed, although special provisions should be taken into account.
Despite the difficulties for law enforcement authorities caused by the solutions described, the standards on the protection of legally sanctioned secrets are relatively complete and, with the exception of the proposed need to take account of the confidentiality of electronically supplied services, do not seem to require specific additions.
2.4. Local jurisdiction of law enforcement authorities
A separate focus should be given to the problem of establishing the law enforcement unit responsible locally in matters concerning offences committed using ICT networks. The problem has both a formal and purely practical dimension, as it determines the speed, effectiveness and transparency of the procedure.
A characteristic feature of prohibited acts performed using the Internet is their specific "multi-sceneness". The perpetrator’s actions often result in a large distance from his whereabouts to those who are often unknown to him, which has several legal and organisational consequences.
Importantly, this is important not only in cross-border terms but also within national jurisdiction.
In cases where the ‘place’ of the action of the perpetrator of a criminal offence is the electronic network (e.g.
the Internet), the establishment of the organisational unit of the law enforcement authorities responsible for conducting proceedings and collecting evidence is not obvious – even (and perhaps especially) in cases where the perpetrator and the victim are active and residing in the Republic of Poland.
In the light of the provisions in force, the place where the offender acted or failed to act or where the effect of the prohibited act occurred or was intended to occur (Article 6(2) (kk).
In the case of "internet" offences, this provision is of particular importance, given that the perpetrator and the victim may be several hundred kilometres apart. In addition, given the possibility of the perpetrator acting as a continuous act (Article 12 kk), places of his committing in material terms can be very many.
The procedural law provides the basis for determining the jurisdiction of the local court, indicating that ‘the court in which the offence was committed is locally competent’ and, if committed in several districts, the court in which the proceedings were initiated (Article 31(1)(3) kpk).
But if it is difficult to determine the place of the act, the directives that have been formulated will come to the aid under Article 32 kpk.
This does not give a clear answer to the question which unit of prosecutors is responsible for conducting the investigation into a specific case.
Information about the current state of the law should be added to the content section 114 section 2 Rules of Procedure of the Public Prosecutor's Office 27 : in cases of criminal offences committed via the electronic and telecommunications network, the preparatory proceedings shall be conducted or supervised in the unit in which the jurisdiction of the perpetrator has acted.
If the place of action of the offender cannot be established, the competent authority for conducting or supervising the proceedings shall be that body in the area of jurisdiction where the offence has been revealed, i.e. where the victim has reported.
Such a solution allows the D.A.'s competent unit to be determined in every case. But it's not perfect. After first, can be a source of competence disputes, unnecessarily prolonging proceedings – the speed of action is important in the context of securing digital evidence.
After second, in the case of perpetrators, for example, of fraud committed against various victims throughout the country, it may be easy to find a situation where investigations against the same person will be conducted simultaneously in many places.
There is currently no effective method of "catching" such situations, which would facilitate the implementation of the principle of economics of proceedings. It is justified, as already stated in the literature, to clarify rules for determining jurisdiction in such cases.[28].
In practice, the investigation is undertaken and conducted most frequently in the unit to which the victim has reported – the perpetrator of a crime committed via the network is often unknown as to the identity and location of the stay until the appropriate procedural activities are carried out (most often related to the issue of the relevant provisions concerning the transmission of telecommunications data).
2.5. Summary and demands for change
Institutions to obtain digital evidence for procedural purposes discussed in this Chapter potentially contribute to this purpose in a variety of factual states. Their use is, in principle, possible in any case of a criminal offence of a computer sense of largo in which materials from electronic devices may be relevant.
The main steps to secure digital evidence through direct actions by law enforcement authorities, in accordance with the guidelines of forensic computing, are to inspect and search.
Fully processable, although not necessarily technically reliable, will obtain evidence by issuing it based on Article 217 kpk (or Article 217 in conjunction with Article 236a kpk).
Taking into account the breakdown of the definitive digital proof adopted in the preceding chapter, such direct safeguarding of the evidence makes it possible to obtain digital evidence of stricto meaning – technical security of evidence from a wide range of electronic media and devices and to submit to research carried out in accordance with the principles of forensic computing.
This is the method devoted to a significant part of the next chapter.
The procedural provisions also allow for reliance on data to be issued by rightholders. However, it should be considered in which situations and to what extent this allows for maintaining their "digital" character from the point of view of forensics.
Telecommunications data or user data using electronic services, and even electronic communications content, are transmitted as a separate data set, in the form of printouts or files. Their reliability is based on trust in the data provider rather than on technical reliability.
Given the technological realities associated with the operation of modern servers and data processing centres, as well as organisational issues, such a compromise seems inevitable.
In recent years, the problem of obtaining data processed outside the jurisdiction of Polish law enforcement authorities has gained great importance. The tools available in this context for international legal assistance cannot be considered sufficient to effectively prosecute many computer crimes.
This is particularly apparent in the case of events related to the activity of "professional" criminals, which is a major problem in the light of modern criminological trends. The progressive improvement of international solutions, in particular in the area covered by European Union law, can be observed.
The current problems with the process use of digital content therefore concern, in particular, access, security and inclusion of remotely processed content – this applies equally to cloud services with limited access (e.g. only for authorised users) and open source data.
On the basis of the previous discussion, a number of changes and modifications to the existing legislation can be made. The following proposals, in particular in the editorial field, may form the starting point for a further debate on the desired directions of change.
After first, Better regulation requires data acquisition, in particular content data, of electronic service providers under the Electronic Services Act.
The current practice of the legal basis for requesting such data is extremely chaotic, most likely due to misinterpretation of the rules and confusion of online service providers 29 with telecommunications companies. To avoid this, it is desirable to modify the provisions in particular Article 218(218a) kpk.
In the editorial field, I suggest that this be done in the simplest possible way: by extending the circle of entities obliged to cooperate with law enforcement authorities on the basis of these provisions to "operators providing electronic services on the basis of other [non-telecommunication] rules".
This will allow the legal state to be structured and simplified in the area of data collection from online service providers practically without interference in the substantive scope of their obligations, which would seem to serve better the intentions of the legislator.
Following such a change, data covering e-mail content, sales platforms, social media or cloud storage would be obtained on the same process basis as telecommunications data. Unfortunately, this will not solve problems with obtaining data processed outside Poland – it requires wider international cooperation.
Coverage of Internet service providers with the identified subject-matter Article 218 kpk may also result in a certain restriction for law enforcement authorities, as only the form of the provision will be appropriate for obtaining data from them (now it should also be so, but, as the practice suggests, applications of this type are formulated by the Police on the basis of the Electronic Services Act, the Police Act, Article 15 kpk or guided without a legal basis).
However, this change will have a positive impact on the level of guaranteeing the rights and freedoms of individuals – practically without limiting the ability to prosecute offenders.
After second, from the point of view of constitutional values, the proposed change under Article 218 and 218a kpk should go hand in hand with the introduction of a statutory “secretary of electronic services” (or the secrecy of electronic services). Its detailed scope and relevance should be subject to a broader expert discussion.
However, it will definitely have a positive impact on the level of implementation of freedom and human rights in Poland. It will also help to stabilise the existing legal situation by harmonising the standards of protection laid down in telecommunications law and in the provisions of the Act on Electronic Services Statement.
It is paradoxical, given the habits of users of communication devices and their capabilities in the modern world, that the content of text messages or telephone calls is heavily protected, while communication with other electronic devices via the network remains unprotected.
Other data arising from the use of network services by the user should also be protected by a valid secret. In the editorial field – only as a starting point for further debate on this issue – I propose that you complete Article 18 of the Act on the Provision of Electronic Services, adding section 7 the following:
„Data in question Under section 1-5, are covered by the secrecy of electronic services, hereinafter “the secret of electronic services”, to which the electronic service provider is obliged to conduct. Subject section 6, the preservation, processing, disclosure, transmission or other use of content or data covered by the secrecy of electronic services infringes the obligation to maintain the secrecy of electronic services, unless: 1) it will be the subject of or will be necessary to perform the service; 2) will take place with the agreement of the recipient; 3) This will be necessary to record these contents and data in connection with lawful commercial practices for the purpose of providing evidence of commercial transactions or communications purposes in commercial activities; 4) This will be necessary for other reasons provided for by law or by separate provisions.’
The introduction of such a provision would, of course, require certain additions and arrangements with the remaining content of the Act, including by imposing criminal sanctions on unlawful infringements of the secrecy of electronic services. The whole of such a solution would introduce similar protection to telecommunications secrecy, while implementing constitutional standards, while at the same time considering the exemptions formulated, it would not adversely affect the actual capabilities of law enforcement authorities.
After third, It should also be necessary to provide for a retention period for electronic services. Today, this issue remains completely unregulated, having a twofold effect: on the one hand, some service providers do not store data at all (or store data only for a short time), preventing effective investigative activities.
on the other hand, some service providers store data on users without a time limit, which creates a difficult to predict threat to their privacy. It would certainly be a very heavy burden on many small service providers to establish clearly the obligation to store all data related to the services provided.
Also considering that the commercial models of many entrepreneurs are based on profiled marketing of operators’ services third, the obligation to automatically delete data after a certain time would certainly not be approved. However, changes seem necessary, and their shape largely depends on the accepted values and philosophy of action.
The assumptions set out here are due to the desire to ensure privacy for users while maintaining the stability of their services, and to the law enforcement authorities' clarity as to what data and how long they are stored by service providers.
The solution could include, for example, the obligation to store all user connection and login data for a certain period of time (as in the case of telecommunications data) after which data storage would only be allowed after the user has given its consent.
At technical level, this would certainly require infrastructure changes for service providers, but the storage of technical data on connections alone should not be an excessive burden.
However, a detailed proposal for the length of the retention period of data on electronically supplied services would require, inter alia, an in-depth analysis in order to ensure that service providers and recipients can effectively pursue claims.
With regard to other data, in particular publicly unavailable "content" data (e.g. messages exchanged on the Internet messaging service or e-mail content), service providers should not have free and permanent access to their content, and this is generally the case at the moment.
At technical level, in the context of the implementation of the ‘electronic service secrets’, this can be achieved using appropriate cryptographic tools.
It is also important from the point of view of the privacy of individuals that the user's "removed" content is actually deleted from the service provider's systems – it is currently impossible to be so sure. The introduction of a regulation requiring the actual removal of user deleted content will have a positive impact on their safety.
There are currently no legal solutions guaranteeing the real privacy of user communication on the network. Newly implemented tools such as "right to be forgotten" (based on Article 14 personal data protection regulations 30 ), are not sufficient.
The scope of their application is quite wide, but they are based excessively on the active activity of users of services and their demand for data deletion.
After fourth, it may be appropriate to modify the rules on procedural control and preservation of conversations. This is due to the need to take into account modern technological realities.
Law enforcement authorities have the actual possibility to use not only passive eavesdropping but also active eavesdropping techniques for persons under control. This is an appropriate solution for the efficient collection of information, but it is important that additional rules and procedural guarantees accompany this.
From legislation Article 237 and Article 241 kpk it follows that procedural control may consist in perpetuating telephone calls, calls other than telephone calls and communications of information, including correspondence sent by e-mail.
It is therefore necessary to specify the nature of ‘information transmissions’ which may be subject to control. The point of operational control is to allow law enforcement authorities to familiarise themselves with the communication of a controlled person with other persons, rather than e.g.
to read the files that this person places on a virtual disk (which would be in the concept of literally interpreted "information messages"). Computer data (using code terminology) not constituting communications aimed at communicating with other persons should be excluded from the scope of the content subject to legal procedural control.
Given the principles of legislative technique, it would be best to add the under Article 241 kpk section 2 in the appropriate wording resulting from the above proposal.
After fifth, in the field of evidence obtained from abroad, it is worth reiterated that the current Rules of Procedure of the D.A.'s office partly renders the European Investigation Order ineffective.
Enabling the use of this procedure directly to district prosecutors would have a positive impact on the speed and efficiency of the proceedings and the negative effects of such a change are difficult to demonstrate rationally.
Changes in this respect require the form of Chapter IV of the Rules of Procedure of the Public Prosecutor's Office. This postulate was already raised in the literature[31].
sixth On the other hand, the area of legislative changes requires a general consideration of issues relating to the acquisition of digital information for criminal proceedings. As has already been stressed, despite many differences, digital evidence belongs to a wide range of factual evidence.
While it is unnecessary to introduce a completely new category of evidence for this reason, it is worth considering introducing a separate process to obtain digital evidence in an appropriate way from the point of view of forensics.
The solutions to current problems must not constitute an act mistakenly referred to as an "expanded search" of information systems. The extension of the search of the IT system to secondary systems in operation is currently not permitted, impossible or significantly impeded by the need for appropriate procedural guarantees.
This illustrates the difficulties associated with the use of classical legal structures in the context of modern events related to the use of computers and the Internet.
The possible introduction of elements of "extended search" or "remote" into the Polish criminal procedure should not mean that extensive surveillance techniques can be used in the criminal process. Unlike operations, process activities should have a relatively high level of transparency.
At the same time, it is difficult to understand and accept situations where law enforcement authorities do not have the formal opportunity to read the content to which remote access is available to the person with whom the inspection or search is carried out.
Traditionally formulated search operation is suitable for finding evidence in the physical world, but clearly inadequate in the context of searching for digital evidence.
Attempts to modify the legal provisions of the search institution (whether through legislative amendments or flexible interpretation of the existing rules) are not the right direction to address this problem.
Consideration should be given to introducing a new type of activity in the procedural law, which is appropriate for the acquisition of materials of digital origin in problematic situations so far. In the event that such a request is too far-reaching, simpler, but incomplete, the solution may be to modify the provisions on the viewing.
The proposed action should consist of specific "views of digital content", adapted in its course and capabilities to the specificity of modern computer technology. Detailed arrangements for such action should allow the practical needs of law enforcement authorities to be reconciled with the principles of the criminal process and the guidelines of criminal computing. The following legislative principles may be set out:
- the requested operation should be carried out by default against all digital data media and information systems examined during the investigation. It should therefore replace current rather chaotic practices in this area;
- the action should be appropriate in the event of a need to take into account open source information in the proceedings (e.g. where necessary, the evidence of the use of content visible on a publicly available website). Currently, the introduction of such data to criminal proceedings is not regulated and is carried out by examining things or places, by means of a description in a memo or by means of a printout of the content of the page attached to the file of proceedings. In the longer term, it would be appropriate to indicate the principles of the credibility of open sources;
- the arrangements for operations should allow officers conducting the operation to have legal access to secondary systems in relation to the original IT system. However, such access should only be possible if the controller of the original IT system has the power to freely access and have certain data resources in the secondary system (for example, situations where it is desirable to check the content stored by the user in the cloud). Currently, such activities are carried out at the border of legality. Such a request shall be fully in accordance with the provisions of the Convention on Cybercrime;
- This should be possible both in the course of another process (e.g. in the course of a search or inspection in the event of the disclosure of electronic equipment) and separately from it (e.g. in the case of the provision of data storage by the person to law enforcement authorities third or the need to examine the equipment secured in the course of another operation;
- an expert or expert in the field of computer science should be required to carry out the activities. This should allow for better, more informed conduct and documentation of the operation and technically correct security of the evidence;
- in the documentation layer, at the level of implementing regulations, it is necessary to draw up a model of the protocol of activities taking into account the specificity of digital content. It should force the conduct of the correct operation to record elements relevant from the perspective of forensic computing.
In the editorial field, it is a rather difficult task to determine the wording of rules introducing this type of activity – this can be done by applying different legislative techniques, modifying the existing provisions or even formulating a new chapter of the procedural law.
In order to facilitate the separate perception of the evidence activities concerning the digital proofs of the stricto sense, it is worth to depart from the previous codend terminology.
Therefore, the proposed action should be separated from such concepts as "view" or "search", so I propose that it be described as "digital content security". In view of the above requests, the addition of the procedural law to the provision may be considered Article 236b the following:
„Article 236b
section 1 If, in the course of a search and detention operation of a device containing computer data or in the course of another operation, the security is to be covered by the information stored in that device or system, the digital content security operation shall be carried out.
section 2. The security of digital content shall also be performed:
- where necessary, safeguard the content or information that is publicly available (open source), regardless of the geographical location of the data;
- where necessary, the security of the content or information data processed in the IT system outside the place of business (secondary system) and to which access is possible by means of an information system located at the place of business (primary system), provided that access to such content or data is possible within the powers of the primary system's competent authority;
- if the secondary system in question Under section 2 point 2, is located outside the country, carrying out a security operation for digital content requires the legal and voluntary consent of the person authorised to disclose the data processed there.
section 3. The security of digital content shall be carried out where possible with the participation of an expert or expert."
If such a request is too far-reaching, the correct direction of the changes may be to modify the provisions on inspection. Among the possible options for such a solution, the simplest seems to be Article 207(1) kpk to read: "When necessary, an inspection of the place, person, item or digital content shall be carried out".
Alternatively, this can be done by adding under Article 207 kpk section 3 in a text-like version Article 236a kpk: ‘section 3.
The provisions on inspection shall apply mutatis mutandis to the operator and the user of the device containing the computer data or the computer system, to the data stored in that device or system or to the medium at its disposal or use, and section 4: „Activities relating to the safeguarding of the content of IT data shall be carried out where possible with the participation of an expert or specialist.’ A model for an adequate protocol of such activities, taking into account the technical circumstances related to digital data of different types, should be set out in the implementing rules, taking into account the guidelines of forensic computing in the area of digital data security and the manner in which the related documentation is kept.
________________________________________
[1] Mr Opitek, Selected aspects of the collection of digital evidence in criminal matters, "Prosecution and Law" 2018, No 7–8, p. 72–73.
[2] It does not require reminding that the content there is sometimes very important for criminal proceedings – after all, social media are a neutral platform for committing crimes (e.g. fraud) and communication between those involved.
[3] Available at: https://www.facebook.com/records/login/, access 19 June 2020
[4] see Facebook, Information for law enforcement authorizations, https://www.facebook.com/safety/groups/law/guidelines/, access 19 June 2020
[5] Google, The most common questions about the processing of user data for legal procedures, https://support.google.com/transparencyreport/answer/7381738, access 19 June 2020
[6] see J. Sobczak, Swoboda of speech in European and North American legal systems, in: J. Cavery (ed.), American human rights protection system. Axiology – institutions – efficiency, Toruń 2015.
[7] P. Opietek, Selected... p. 71.
[8] Attorney General PG V WM 082/2/12 to 5 December 2012 on a meeting in Washington with representatives of the U.S. Department of Justice on free speech (unpubl.).
[9] Data provided under transparency policy for: Google Transparency Report, https://transparencyreport.google.com/user-data/overview?t=table, access 19 June 2020
[10] A “case requiring immediate response” means situations of threat to the life or health of a person (abductions, terrorist threats, etc. serious events). Behind: Google, The most common questions about processing user data for legal procedures, https://support.google.com/transparencyreport/answer/7381738, access 19 June 2020
[11] So we're talking about so-called white-talking; see B. Stromczyński, P. Waszkiewicz, White interview in law enforcement practice on the example of the use of social networks, “Prosecution and Law” 2014, No 5, p. 146–169.
[12] A. Lach, Fighting illegal content on the Internet, Toruń 2015, p. 15.
[13] So those at the lowest levels of protection of classified information in light Article 5 Act dated 5 August 2010 on the protection of classified information (Journal of Laws of 2019, item 742)
[14] A. Sakowicz (ed.), (ed.), Code of Criminal Procedure. Commentary, Warsaw 2016, p. 551. Cf. Supreme Court judgment 16 July 2009, reference no. V KK 20/09, Legal Information Service Wolters Kluwer, LEX nr. 519629., p. 571.
[15] see G. Szpor, A. Gryszczyńska, Lexicon of Mystery, Warsaw 2016.
[16] Act dated 28 January 2016 – Law on the prosecution (Journal of Laws of 2021, item 66).
[17] Digital material covered by the mystery of confession would certainly be rare, but one can imagine its existence, even against religious rules.
[18] It is also important to bear in mind the limitations resulting from Article 180(3)(4)(5) kpk, concerning the general prohibition on the repeal of journalistic secrecy as regards the identification of journalism sources
[19] Regulation of the Minister of Justice dated 9 September 2017 on how to deal with the minutes of hearings and other documents or objects to which the obligation to keep classified information confidential or to keep a secret related to the exercise of a profession or function (Journal of Laws of 2017, item 1733).
[20] This also applies to a person whose defense secret concerns him as a suspect or accused person. Cf. Supreme Court resolution of 16 June 1994, reference no. I KZP 5/94, Judgment of the Supreme Court Criminal Chamber and Military Chamber 1994, No 7–8, item 41.
[21] Order of the Supreme Court of 26 October 2011, reference no. I KZP 12/11, Judgment of the Supreme Court Criminal Chamber and Military Chamber 2011, No 10, item 90.
[22] M. Chrabkowski, K. Gwizdała, Security of electronic evidence, ‘Prosecution and Law’ 2015, p. 166
[23] Act dated 29 August 1997 – Bank law (Journal of Laws of 2020, item 1896 as amended).
[24] As the Supreme Court pointed out, the scope of this secrecy was based on the principle of "maximumisation", see Supreme Court resolution with 23 May 2006, reference no. I KZP 5/06, Judgment of the Supreme Court Criminal Chamber and Military Chamber 2006, No 6, item 55.
[25] Cf. D. Taberski, Proceedings on Internet fraud cases, “Prosecution and Law” 2018, No 6, p. 72
[26] Notabene similar solution, although as a result of internal regulations, was adopted in the structures of many IT corporations – a good example of this are the activities of the portal administrator facebook.com, which accepts requests for data from law enforcement authorities only to a limited extent and fully and without additional formalities implements requests from authorised users
[27] Regulation of the Minister of Justice dated 7 April 2016 – Regulations
[28] D. Taberski, Proceedings on Internet fraud cases, “Prosecution and Law” 2018, No 6 p. 78. Cf. P. Peterek, Time and place of the crime committed via the ICT network – practical solutions in the light of procedural economics, in: J. Kosiński (ed.), ICT Crime, Szczytno 2013, p. 142–151
[29] By this, I mean entities other than those referred to as "Internet service providers" or "Internet providers". The Internet as a service (connection to the Internet) is carried out by telecommunications operators and "Internet service providers" provide services on the network – this distinction is similar to the e-mail and transmission services mentioned earlier.
[30] Regulation (EU) 2016/679 dated 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46 (General Data Protection Regulation)
[31] Lt. P. Opietek, Selected..., p. 70–71. The same postulate was rightly repeated in: P. Olber, Legal-technical aspects of securing and obtaining electronic evidence from cloud computing, doctoral work, non-publ. Warsaw 201