How Should Electronic Data Be Reviewed in Cybercrime Cases?
Electronic data in cybercrime cases cannot be assessed by content alone. This guide examines source, integrity, identity attribution, and probative value, including chat records, forensic images, hash values, platform data, online extraction, procedural defects, and authenticity defects.
In cybercrime cases, electronic data such as chat records, transaction records, login logs, IP addresses, data extracted from mobile phones, backend databases, and server logs often occupies a central place in the evidentiary record.
But the volume and technical nature of electronic data do not make it inherently more reliable than conventional forms of evidence.
The fact that a chat record genuinely exists does not by itself establish who was using the account. A mobile-forensics output containing large volumes of data does not mean that the source of the data, the extraction process, and its integrity are necessarily beyond question. Nor does the fact that an account is registered in a person’s name establish that every operation performed through that account was carried out by that person.
Reviewing electronic data therefore requires more than asking:
“What does this data say?”
It also requires asking:
Where did the data come from? How was it obtained? Did anything occur during collection, examination, or transfer that could affect its authenticity? To whom can it reliably be attributed? And what, ultimately, does it prove?
From a criminal-defense perspective, these questions can be organized around four dimensions: source, integrity, identity attribution, and probative value. This is simply a practical method for reviewing a case. It is not a set of four statutory elements, and a problem in any one dimension does not, by itself and without reference to the applicable legal rule, mean that the evidence must automatically be excluded.
1. First, What Counts as “Electronic Data” in Chinese Criminal Proceedings?
Electronic data is not limited to chat histories or screenshots from a mobile phone.
Article 50 of the Criminal Procedure Law of the People’s Republic of China expressly recognizes “audio-visual materials and electronic data” as categories of evidence. The 2016 Provisions issued jointly by the Supreme People’s Court, the Supreme People’s Procuratorate, and the Ministry of Public Security further define electronic data as data generated in the course of the events underlying a case, stored, processed, or transmitted in digital form, and capable of proving facts relevant to the case.
Common examples include information published on online platforms; SMS messages, emails, instant messages, and group-chat information; user-registration and identity-authentication information; electronic transaction records, communications records, and login logs; and electronic files such as documents, images, audio or video files, digital certificates, and computer programs.
Cybercrime cases may also involve browsing and operation records, records showing the installation, operation, or deletion of software, malicious programs, website source code, execution scripts, system logs, application logs, database files, and metadata showing when files were created, accessed, or modified.
Electronic data can therefore do more than show what was said. It may also help determine:
who was using a system, when it was used, what device was used, what operation was performed, and what result followed.
At the same time, a witness statement, victim statement, or statement or defense made by a criminal suspect or defendant does not become “electronic data” merely because it is stored on a computer, optical disc, or other electronic medium. The 2016 Provisions expressly distinguish those forms of evidence from electronic data.
2. First Identify What You Are Actually Looking at in the Case File
When reviewing a case file, a lawyer may encounter several different materials at the same time:
printed chat histories, screenshots from a mobile phone, electronic-data extraction records, forensic images, database files, electronic-data examination records, and outputs generated by forensic software.
These are not all the same type of material.
A useful first step is to distinguish among:
the original storage medium, electronic data extracted from that medium, a forensic image, a backup copy of the electronic data, and screenshots or printouts created for review or presentation.
Because electronic data can exist independently of the physical medium on which it was originally stored, the relationship among an original storage medium, extracted data, a forensic image, a backup copy, and a printout should not be reduced to the traditional documentary distinction between an “original” and a “photocopy.”
Where the original storage medium can be seized, the current rules generally require it to be seized and sealed. Where it cannot be seized, is impracticable to move, or another prescribed circumstance applies, electronic data may instead be extracted in accordance with the applicable procedures.
The 2021 Provisions on the Handling of Cybercrime Cases by People’s Procuratorates also contain specific requirements for reviewing forensic images, including information identifying the original storage medium, the tools and methods used to create the image, the imaging process, and integrity check values.
Accordingly:
The absence of the original mobile phone from the materials transferred with the case does not, by itself, establish that the electronic data is unreliable or unusable.
The further questions are:
Why was the original storage medium not transferred?
How was the data extracted?
Where is the original medium located?
How is the source of the data documented?
How was integrity protected and verified?
Screenshots and printouts likewise cannot be treated as a single category.
The current rules governing electronic-data collection by public security organs permit printing, photography, or video recording in specified circumstances and require information to be recorded about why that method was used, where the data was stored, and the characteristics and location of the original medium.
In practice, however, it is still necessary to distinguish among:
First, materials created by investigators through screenshots, printouts, or video recording as a prescribed method of preserving electronic data as evidence;
Second, printouts or screenshots created merely to transfer, review, or present electronic data that had already been lawfully obtained; and
Third, chat screenshots independently supplied by a victim, witness, reporting person, or another person connected with the case.
Those materials arise through different processes, and the ways in which their authenticity and integrity are verified are not necessarily the same.
Accordingly:
A screenshot is not inherently invalid, but neither does the fact that a screenshot “looks genuine” complete the review of electronic data.
3. Authenticity: Where Did the Data Actually Come From?
Reviewing the authenticity of electronic data involves more than asking whether a file appears to have been fabricated or altered.
Article 110 of the 2021 Interpretation of the Supreme People’s Court on the Application of the Criminal Procedure Law requires examination of matters such as the original storage medium, the source of the electronic data, digital signatures or certificates, whether the collection and extraction process can be reproduced, whether data was added, deleted, or modified, and whether integrity can be ensured.
The 2016 joint Provisions adopt a substantially similar framework.
A chat database extracted from a mobile phone therefore raises at least two separate questions:
First, did this data actually come from the mobile phone, account, or system from which it is said to have come?
Second, from extraction and copying through examination, transfer, and final presentation, did anything occur that affected its authenticity?
Reliability of source and preservation of integrity after extraction are related, but they are not the same issue.
Where a forensic image was created, further review may include:
which original storage medium the image corresponds to;
whether identifying information for that medium was adequately recorded;
what tools and methods were used to create the image;
whether the imaging process was documented; and
whether the relevant integrity check values correspond.
Electronic data also does not enter criminal proceedings only through the familiar route of “the police seized the phone and extracted the data.”
Article 54 of the Criminal Procedure Law permits electronic data and certain other evidentiary materials obtained by administrative authorities in the course of administrative law enforcement and case handling to be used in criminal proceedings. Article 75 of the 2021 SPC Interpretation further requires such materials to be verified in court and to have been collected in accordance with the applicable laws and administrative regulations.
Accordingly, the first question should not always be whether “two police officers signed the extraction record.”
The better starting point is:
Was the data collected or extracted by an investigative authority, transferred from an administrative enforcement authority, supplied by a network service provider in response to a formal request, or provided by another person before entering the criminal case?
Different sources may trigger different procedural requirements.
4. Hash Values Matter, but They Are Not a “Certificate of Authenticity”
Cybercrime cases frequently involve integrity check values calculated using hash algorithms such as MD5 and SHA, commonly referred to as hash values.
Current rules recognize the calculation of integrity check values as one important means of protecting and verifying the integrity of electronic data. Integrity may also be examined through such matters as the seizure and sealing status of the original storage medium, recordings of the collection or extraction process, backup copies, or access and operation logs generated after data was frozen.
But a hash value principally addresses this question:
Did a particular data object remain unchanged between the relevant points in time?
It does not, by itself, establish:
whether the correct object was extracted in the first place;
whether the data had already changed before extraction;
which account or device the data actually came from;
who controlled or used the account; or
what legal significance the data has in the case.
A further distinction is therefore necessary between:
“Has the particular dataset that was extracted remained unchanged?”
and:
“Was all electronic data relevant to the case comprehensively and completely extracted?”
For example, investigators might extract only chats from a particular time period or only records matching specified search terms and then calculate a hash value for that dataset.
Even if the hash value remains identical thereafter, this establishes only that the particular extracted dataset did not undergo a corresponding change.
It does not automatically establish:
whether surrounding messages were omitted;
whether other relevant data existed in the original database;
what search or filtering criteria were used; or
whether omitted material could change the meaning of the extracted content.
Accordingly:
A matching hash value is not the same thing as proof that the electronic data is authentic, complete, and sufficient to establish that the defendant committed the alleged crime.
There are additional evidentiary steps between those propositions.
5. Legality of Collection: First Identify the Actual Collection Route
There is no single sequence of steps that every electronic-data investigation must follow.
Under the current rules governing electronic-data collection by public security organs, investigators may use one or more methods depending on the circumstances of the case, including:
seizing and sealing the original storage medium; on-site extraction; online extraction; freezing electronic data; and obtaining electronic data by formal request.
The current rules provide that online extraction may be used for electronic data that has been publicly released and electronic data stored on remote computer information systems located within China.
A lawyer should therefore first identify which route was actually used and then review the procedures and technical records required for that particular route.
For example:
Where a mobile phone or computer was seized and sealed, the review may focus on identification of the original medium, the seizure list, the condition of the seal, and the connection between the medium and the case.
Where data was extracted on site, relevant questions may include why the original medium could not be seized, what was extracted, the source, time and place of extraction, the method and process used, the original storage path, and the integrity check value.
Where data was extracted online, relevant issues may include how the system was accessed, when extraction occurred, the tools and methods used, the network address or storage path, and the integrity-verification process.
Where electronic data may not be capable of being extracted again or may change, the review should also determine whether video recordings, photographs, screen captures, or other materials documenting the extraction process were created as required.
Online Extraction and Remote Network Inspection Are Not the Same Procedure
The current rules governing electronic-data collection by public security organs separately provide that, during online extraction, if investigators need to conduct further analysis to determine the scope of data, display or describe the content or condition of electronic data, install a new application on the remote system, cause the remote system to generate new data other than data produced through normal operation, or collect information about system status, architecture, internal relationships, directory structure, or operating methods, the procedure for remote network inspection applies.
The two concepts should therefore not be treated as interchangeable merely because both involve accessing data through a network.
Data Obtained from Online Platforms Has Its Own Review Path
Large amounts of payment-account, social-platform, online-service, and backend data in cybercrime cases are obtained through formal requests to network service providers.
Article 14 of the 2022 Opinions on Several Issues Concerning the Application of Criminal Procedure in Handling Information Network Crime Cases provides for formal legal documentation when public security organs request electronic data from network service providers.
Where a network service provider supplies electronic data in the form of a data message, the prescribed framework requires measures to protect integrity and an electronic certification document. Procuratorates and courts may further verify matters such as electronic signatures, digital watermarks, integrity check values, and the correspondence between the certification document and the number of the formal data request.
Platform-produced data therefore should not simply be reviewed through the same model used for a seized mobile phone — “seizure, sealing, forensic imaging.”
Data Obtained Before Formal Case Filing Is Not Automatically Unusable
The 2016 Provisions expressly provide that electronic data collected or extracted during preliminary inquiry may be used as evidence.
The 2022 Opinions also establish an investigation-and-verification procedure for information-network crime cases where further inquiry is needed to determine whether the threshold for formally opening a criminal case has been met.
Electronic data and other materials lawfully collected during investigation and verification may be used as evidence in accordance with the applicable rules. If such materials are used as evidence, they must be transferred with the case together with the relevant materials approving the investigation and verification. Where the evidentiary materials have been verified and their collection complied with the applicable requirements, they may be used as a basis for deciding the case.
Accordingly, the fact that:
“the data was obtained before the criminal case was formally filed”
does not, standing alone, establish that the evidence was unlawfully obtained or unusable.
The appropriate inquiry is what procedure was being used at that time, whether the required approval existed, what investigative measures were permissible under that procedure, and whether the relevant approval materials were transferred with the case.
The “Two or More Investigators” Requirement Must Also Be Applied to the Correct Source of Evidence
For collection and extraction by investigative organs, the 2016 Provisions contain requirements concerning participation by two or more investigators. The current rules governing electronic-data collection by public security organs contain corresponding requirements for public security investigations. Article 112 of the 2021 SPC Interpretation likewise treats the number of personnel involved as one factor in reviewing the legality of collection.
But where electronic data was first lawfully obtained by an administrative authority and later entered criminal proceedings, or where a network service provider supplied data in response to a formal request, the applicable rules must be identified according to that particular source.
A collection procedure applicable to public security organs should not be mechanically applied to every form of electronic data entering a criminal case.
Regulatory Update — As of August 2026
In May 2026, the Ministry of Public Security released a draft revision of the Rules on Electronic Data Collection for public comment. The draft is intended to revise the 2018 Rules on Electronic Data Collection in Criminal Cases by Public Security Organs, and the public-comment period closed on June 21, 2026.
The published materials state that the draft remains subject to revision based on comments and completion of the applicable procedure for issuing departmental normative documents.
As of the date of this article, no formally issued and effective replacement rules have been identified. The discussion in this article therefore continues to rely on the existing rules. The 2026 draft is mentioned only as a regulatory development and is not treated as current law.
6. “The Account Is Registered to Him” and “He Performed the Specific Act” Are Different Questions
This distinction is especially important in cybercrime cases.
Real-name registration information, mobile-number subscriber information, device ownership, and bank-account registration records may all be relevant to determining the correspondence between an online identity and a real-world person.
But those facts are not the same as establishing:
who actually controlled, logged into, and used the account during the relevant period;
or:
who carried out a particular chat, login, transfer, or other online act alleged in the case.
The 2016 electronic-data Provisions require identity attribution to be assessed in light of such evidence as IP addresses, online activity records, ownership or use of the terminal device, witness testimony, and statements or defenses of the criminal suspect or defendant.
The 2021 Procuratorate Provisions further refer to account-authentication information, chat and file content, domain names, IP addresses, MAC addresses, and cellular base-station information when assessing identity.
An account can therefore be broken down into at least three separate questions:
In whose name is the account registered?
Who actually controlled, logged into, and used it during the relevant period?
Who performed the particular operation alleged in the case?
All three questions may ultimately point to the same person. But they do not necessarily do so.
IP addresses, MAC addresses, cellular base-station information, and device identifiers likewise should not be treated mechanically as a “digital identity card.”
Their probative significance depends on how they were obtained, the relevant timing, the network environment, the manner in which devices were used, and whether they are corroborated by other evidence.
Accordingly:
Real-name registration does not automatically establish actual control, and actual control does not automatically establish that every specific operation was performed by that person.
7. Data May Be Authentic Without Establishing the Elements of the Offense
Even after the authenticity of electronic data has been established, its relevance and probative value must still be examined.
For example, the presence of a particular group chat, software application, or browsing record on a person’s phone may first establish only that the corresponding data exists.
Using that data to establish:
knowledge;
criminal intent;
shared criminal intent;
actual assistance;
the amount attributable to the offense; or
illegal gains
requires further examination of when the data was created, its context, the course of conduct, and other evidence in the case.
The Provisions on the Handling of Cybercrime Cases by People’s Procuratorates require examination of identity, objective conduct, the subjective element, the circumstances and consequences of the alleged crime, and the relationship between electronic data and other evidence.
The continuing questions should therefore be:
What does this data actually prove?
and:
What does it not prove by itself?
For example:
A chat record may establish that two people communicated, but it does not automatically establish that they formed a shared criminal intent.
A transfer into an account may establish a flow of funds, but it does not automatically establish that the recipient knew the funds were connected to criminal activity.
The presence of a particular application on a device may establish that the software existed on the device, but not necessarily that the defendant personally used it to commit an offense during the relevant period.
There is still an evidentiary step between the existence of electronic data and proof of the facts constituting the alleged offense.
8. Chat Records Should Be Read in Context; Isolated Keywords Should Not Substitute for Proof of Knowledge
Chat records are among the most common forms of electronic data in cybercrime cases.
The dispute is often not whether the chat content was fabricated entirely, but whether:
the material presented in the case file is complete and whether key statements have been separated from the context in which they were made.
If investigators extract only several keywords, a few screenshots, or a limited period of conversation without the surrounding exchanges, the same words may carry a materially different meaning.
Review of chat records may therefore include questions such as:
Is the timeline continuous?
Are there obvious gaps in the surrounding conversation?
Who participated?
Which message does a quoted or replied-to message refer to?
How do text, files, images, and links relate to each other?
Can key statements be corroborated by login records, transaction data, operation logs, or other evidence?
Particular attention may also be required for:
slang, code words, abbreviations, colloquial expressions, industry terminology, and terminology used internally by a particular group.
Article 115 of the 2021 SPC Interpretation expressly calls for attention to whether explanations have been provided for nicknames, coded language, colloquial expressions, dialect, and other content in electronic data that may be difficult to understand.
An investigator’s personal interpretation of a code word or abbreviation therefore should not, by itself, determine that the expression has a particular criminal meaning.
But the opposite proposition would also be too broad:
“A single chat message can never establish knowledge.”
In a particular case, a single message may have substantial probative value.
The real questions are:
what the message actually says, the context in which it was created, and whether it is corroborated by patterns of conduct, relationships among participants, profits received, transaction methods, other communications, and objective conduct.
What should be avoided is:
mechanically inferring knowledge from an isolated keyword removed from its context.
9. Examination Records, Expert Opinions, and Reports from Designated Institutions Should Not Be Read Only for Their Bottom-Line Conclusions
Complex cybercrime cases may involve:
data recovery;
analysis of software functionality;
identification of malicious code;
database analysis;
server-log analysis; and
large-scale searching, correlation, statistical analysis, and comparison of data.
The case file may therefore contain electronic-data examination records, expert opinions, reports issued by designated institutions on specialized issues, and other inspection or testing materials.
These materials do not necessarily have the same author, procedural basis, or evidentiary character.
They should not all be described as “expert reports” merely because they were produced by technical personnel.
The 2016 Provisions distinguish among electronic-data examinations and examination records, expert opinions issued by judicial appraisal institutions, and reports issued by institutions designated by the Ministry of Public Security on specialized issues. For cases directly accepted by a People’s Procuratorate, reports may also be issued by institutions designated by the Supreme People’s Procuratorate.
Here, a judicial appraisal institution refers to a licensed forensic appraisal institution operating within China’s judicial-appraisal framework.
The current rules governing electronic-data collection by public security organs separately regulate electronic-data examination as well as inspection and appraisal procedures. The 2021 Procuratorate Provisions further provide that inspection or testing reports issued by institutions other than appraisal institutions may be reviewed by reference to the relevant rules governing expert opinions.
Accordingly, when receiving a technical document, the first question should be:
What type of evidentiary material is this?
The review can then consider:
What was analyzed?
Where did the underlying data come from?
What tools, methods, and steps were used?
What technical information does the applicable rule require to be recorded?
Can the analysis and conclusion be meaningfully verified?
Does the conclusion go beyond what the underlying method can support?
A further distinction should be made between:
underlying electronic data
and:
derived results produced through searching, filtering, correlation, deduplication, statistical analysis, comparison, or other processing.
For example, a case file may state:
“Analysis identified XX items of case-related data.”
or:
“Statistical analysis determined the amount involved to be RMB XX.”
Those final figures are not necessarily the original electronic data themselves.
The 2016 Provisions permit electronic-data examinations involving recovery, decryption, statistical analysis, correlation, and comparison and require explanations concerning matters such as statistical quantities and data identity.
A derived statistical result should therefore prompt further questions:
Which underlying data was used?
What filtering conditions were applied?
What was the statistical methodology?
Was deduplication performed?
How were refunds, reversals, duplicate transactions, or obviously unrelated funds treated?
How was the final figure derived step by step from the underlying data?
The point of technical review is not to insist that every case must record the same software version or every possible technical parameter.
The question is whether:
the information required by the applicable rules is present and whether the materials are sufficient to permit meaningful verification of the method and conclusion.
10. Voluminous Evidence: Several Different Rules Should Not Be Conflated
Cybercrime cases may involve large numbers of victims, accounts, transactions, and other evidentiary materials.
Current rules do not address all of these problems through a single concept of “sampling.” Different mechanisms apply to different evidentiary and proof-related difficulties.
First: Determining Facts When Relevant Testimonial Evidence Cannot Be Collected Individually
Article 21 of the 2021 Provisions on the Handling of Cybercrime Cases by People’s Procuratorates provides that, where objective conditions make it impossible to collect relevant testimonial evidence individually, electronic data, documentary evidence, and other evidentiary materials recording facts such as the number of victims, the number of affected computer information systems, and the amount of funds involved may be considered together with the evidentiary record as a whole, after reviewing the arguments and defense submissions raised by the defendant and defense counsel, in determining the relevant criminal facts.
This mechanism addresses:
whether relevant criminal facts may be determined by considering electronic data, documentary evidence, and the evidentiary record as a whole when relevant testimonial evidence cannot objectively be collected person by person.
It is neither sample-based verification nor the selection of a proportion or quantity of evidence from a larger body of materials.
Second: Sample-Based Verification
Article 22 of the 2021 Procuratorate Provisions provides that, where there are large quantities of similar evidentiary materials and objective conditions make it impossible to verify them all when determining whether they have the same nature, characteristics, or function, sample-based verification may be used.
This mechanism addresses:
whether sampling may be used to verify the shared nature, characteristics, or function of similar materials when all such materials cannot be verified.
Third: Selecting Evidence According to a Specified Proportion or Quantity
Article 20 of the 2022 Opinions addresses exceptionally voluminous evidentiary materials having the same nature, characteristics, or function.
Where objective conditions make item-by-item collection impossible, the rule requires evidence to be selected according to a specified proportion or quantity, and the selection must be explained and justified. Procuratorates and courts must also examine whether the method and process used to collect the evidence were scientifically sound.
This mechanism addresses:
how evidence is to be selected when objective conditions make item-by-item collection impossible.
Sample-based verification and selective collection are related concepts, but they are not the same rule.
Fourth: The Special Rule for Determining the Amount Attributable to the Offense Through Certain Accounts
Article 21 of the 2022 Opinions establishes a more specific rule for information-network crime cases involving a particularly large number of persons.
Where objective conditions make it impossible to collect evidence proving the relevant matters individually and to verify, person by person, the sources of funds in the accounts involved, but bank-account or non-bank payment-account transaction records and other evidentiary materials are sufficient to establish that the relevant accounts were primarily used to receive or transfer funds involved in the case, the amount received by the relevant account may, subject to the conditions prescribed by the rule, be treated as the amount attributable to the offense.
This does not apply where the criminal suspect or defendant provides a reasonable explanation, and objections raised by third parties must also be examined in accordance with law.
This is not simply:
“sample a few incriminating transactions and presume that everything else is criminal.”
It is a specific rule for determining amounts in information-network crime cases where the prescribed conditions are satisfied, including a particularly large number of persons and sufficient evidence concerning the principal use of the account.
Defense review should therefore still examine:
whether the prerequisites for applying the rule are actually met;
whether the evidence is sufficient to establish that the account was primarily used to receive or transfer funds involved in the case;
whether a reasonable explanation offered by the criminal suspect or defendant was examined; and
whether third-party objections and funds unrelated to the case were properly addressed.
Article 20 of the 2022 Opinions also provides that, where reasonable doubt concerning the relevant facts cannot be eliminated, a determination favorable to the criminal suspect or defendant should be made.
A more accurate conclusion is therefore:
Cases involving voluminous evidentiary materials may require different methods of collecting, verifying, and using evidence to establish facts, but those methods do not permit criminal proof requirements to be lowered without satisfying the prescribed legal conditions.
11. Procedural Defects and Defects Affecting Authenticity Should Be Analyzed Separately
Objections to electronic data should not all be reduced to:
“The procedure was unlawful, so all of the data is invalid.”
Current rules distinguish among different types of problems.
First: Procedural Defects That May Be Corrected or Reasonably Explained
Article 27 of the 2016 Provisions and Article 113 of the 2021 SPC Interpretation identify procedural defects such as failure to transfer electronic data in a sealed condition, missing signatures or seals on records or lists, and unclear identification of the name, category, or format of the data.
Where such defects are corrected or reasonably explained, the evidence may be used.
Where they cannot be corrected or reasonably explained, the electronic data may not be used as a basis for deciding the case.
Second: Problems That Prevent Authenticity from Being Reliably Established
Article 28 of the 2016 Provisions and Article 114 of the SPC Interpretation address circumstances such as fabrication or alteration, inability to determine whether the data is genuine, additions, deletions, or modifications affecting authenticity, and other circumstances in which authenticity cannot be assured.
Electronic data falling within those circumstances may not be used as a basis for deciding the case.
One further distinction is necessary:
The fact that electronic data changed at some point does not mechanically mean that it must always be rejected.
Article 44 of the 2021 Procuratorate Provisions provides that, even where data was added, deleted, or modified, it may still be used where an expert appraisal, confirmation by the parties, or other means establishes that important data relevant to the case did not change, or where the original state can be restored and the process of change can be determined.
The more accurate sequence of review is therefore:
What changed?
When and at what stage did it change?
Why did it change?
Did any important data relevant to the case actually change?
Can the original state be restored, and can the process of change be determined?
Only then should the reviewer determine whether the problem is a procedural defect that can be addressed through correction or explanation, or a defect that prevents the authenticity of the electronic data from being reliably established.
12. A Practical Four-Dimensional Framework for Reviewing Electronic Data in Cybercrime Cases
Where a case contains large volumes of electronic data, reviewing the file page by page without first structuring the issues can quickly become inefficient.
One practical method is to organize the review around four dimensions.
First: Source
Ask:
Which device did the data come from?
Which account?
Which network platform?
Which server?
Was it obtained by an administrative authority or an investigative authority?
Was it extracted on site, extracted online, or obtained from a platform?
Where is the original storage medium?
Second: Integrity
Ask:
Did anything occur during acquisition, extraction, copying, forensic imaging, examination, transfer, or presentation that could affect authenticity?
The relevant materials may include sealing records, extraction records, integrity check values, backups, access logs, and video recordings, depending on the actual collection route used in the case.
The purpose is not to impose an identical fixed sequence on every case.
Third: Identity Attribution
Distinguish among:
the registered account holder;
the owner of the device;
the person possessing the device;
the person actually controlling the account; and
the person who performed the operation at the relevant time.
Then examine account-authentication information, IP and device information, login records, chat content, fund flows, cellular base-station information, and other evidence together.
Fourth: Probative Value
Even if no obvious problem exists in the first three dimensions, the ultimate question remains:
What fact in the criminal case does this electronic data actually prove?
Does it establish the specific act?
Knowledge?
Shared criminal intent?
The amount attributable to the offense or illegal gains?
Or is additional evidence still required?
These four dimensions are merely a practical method for organizing a lawyer’s review of electronic data. They are not four statutory elements.
A problem in one dimension should not automatically produce the conclusion that the evidence “must be excluded.”
The next step is still to apply the specific legal rule and determine whether the issue:
requires additional proof, can be corrected or reasonably explained, affects evidentiary weight, or reaches the level at which the electronic data may not be used as a basis for deciding the case.
13. Frequently Asked Questions
1. If the Original Phone Is Not Available, Does That Mean the Chat Records Cannot Be Used as Evidence?
No.
Current rules do not require the original mobile phone to be transferred with the case in every electronic-data case.
Where the original storage medium cannot be seized, is impracticable to move, or another prescribed circumstance applies, electronic data may be extracted in accordance with the applicable rules. In specified situations, electronic data may also be preserved through printing, photography, or video recording.
The important questions remain:
Why is the original medium unavailable?
How was the data obtained?
Was its source documented?
Did the extraction process comply with the applicable rules?
Can authenticity and integrity be verified through other materials?
2. If There Is a Hash Value, Does That Mean the Data Must Be Authentic?
No.
An integrity check value primarily helps determine whether a particular data object changed during a relevant period.
It does not, by itself, establish who originally generated the data, who actually used the account, whether the correct material was extracted, or whether all data relevant to the case was extracted.
3. If Crime-Related Keywords Appear in a Chat, Does That Prove the Defendant Had Knowledge?
Not mechanically.
The meaning of the keyword, the full surrounding conversation, the identity of the other participant, timing, frequency of conduct, transactions and profits, the person’s level of knowledge and professional background, and other evidence should all be considered.
But the opposite proposition is also too broad: a single message may have substantial probative value in a particular case.
The key is not to substitute an isolated keyword removed from context for a complete analysis of the required mental state.
4. If the Phone Belongs to the Defendant, Can All Data on It Automatically Be Attributed to the Defendant?
No.
Ownership of the device, actual use of the device, control of an account, and responsibility for a particular online operation are different factual questions.
Real-name information, IP addresses, MAC addresses, cellular base-station information, and login records may all assist in identity attribution, but they ordinarily still need to be assessed in light of the technical context and other evidence.
5. Does a Procedural Error Mean the Entire Dataset Cannot Be Used?
Not necessarily.
The first distinction is between:
a procedural defect that may be corrected or reasonably explained
and:
a substantive problem that prevents the authenticity of the electronic data from being reliably established.
Even where data was added, deleted, or modified, it remains necessary to determine whether important data relevant to the case actually changed, whether the original state can be restored, and whether the process of change can be determined.
The mere fact that the data changed does not, by itself, determine whether the data may be used as a basis for deciding the case.