Abstract
The article is devoted to the topical issues of digital evidence collection within the law, in accordance with the requirements of personal data protection and confidentiality. The procedure for collecting digital evidence is extremely important, as it affects its reliability, admissibility in court and the ability to reproduce events. The rapid development of digital technologies has led to an increase in the number of offenses in cyberspace, and this, in turn, has increased the relevance of study ing the process of digital evidence collection. The author examines the main stages of this process: from identifying and recording evidence to documenting, preserving and analyzing it. Particular attention is paid to the importance of following the sequence of actions to ensure the integrity and authenticity of evidence. The main threats associated with improper data collection are outlined, including the risk of loss, distortion, or forgery of digital traces. International standards and best practices in digital forensics that regulate the handling of electronic evidence are analyzed. Improving approaches involves unifying pro cesses in accordance with international standards, which will facilitate the investigation of transnational crimes. The author emphasizes the importance of an interdisciplinary approach that combines legal, tech nical and organizational aspects necessary to ensure the admissibility of collected evidence in court practice. It is noted that increased at tention to the protection of personal data and confidentiality requires a clear balance between the efficiency of evidence collection and the observance of users’ rights.
References
Lewulis, P. (2022). Collecting Digital Evidence from Online Sources: Deficiencies in Current Polish Criminal Law. Crim Law Forum. Vol. 33. DOI: 10.1007/s10609-021-09430-4 (access date: 24.03.2025).
Sun, J.-R., Shih, M.-L., Hwang, M.-Sh. (2015). A survey of digital evidences forensic and cybercrime investigation procedure. International Journal of Network Security. Vol. 17.
Romaniuk, V., Fomina, T. (2024). The Procedure for Collecting Electronic (Digital) Evidence in Criminal Proceedings on Collaboration Activities. Bulletin of the Criminological Association of Ukraine. Vol. 32 (2). DOI: 10.32631/vca.2024.2.25 (access date: 24.03.2025) [in Ukrainian].
Hutsaliuk, M. V., Antoniuk, P. Ye. (2021). On the Essence of Electronic (Digital) Information as a Source of Evidence in Criminal Proceedings. Criminalistics Bulletin. Vol. 33 (1). DOI: 10.37025/1992-4437/2020-33-1-37 (access date: 24.03.2025) [in Ukrainian].
Romaniuk, V. V., Ablamskyi, S. Ye. (2024). Criteria for the admissibility of digital (electronic) evidence in criminal proceedings. Law and Safety. Vol. 2 (93). DOI: 10.32631/pb.2024.2.13 (access date: 24.03.2025) [in Ukrainian].
DSTU ISO/IEC 27037:2017 Information technology. Protection methods. Guidelines for the identification, collection, acquisition and preservation of digital evidence (2018) [in Ukrainian].
IETF RFC 3227 Guidelines for Evidence Collection and Archiving. URL: https://datatracker.ietf.org/doc/html/rfc3227 (access date: 24.03.2025).
NIST SP 800-86 Guide to Integrating Forensic Techniques into Incident Response.