Course Lecturer/ Justyna Sarkowicz
Course Overview
This course explores the central role of electronic evidence in modern criminal justice systems, focusing on cybercrime, fraud, terrorism, and organized crime. Students will study the technical, jurisdictional, and procedural challenges investigators face when handling volatile digital data, coordinating across borders, and balancing state security with fundamental privacy rights.
Lecture 1.1: What is Electronic Evidence?
Definition and central role in modern criminal proceedings.
Types of electronic evidence: emails, metadata, IP addresses, cloud files, server logs, and chat messages.
Lecture 1.2: Volatility and the Intangible Nature of Data
Why digital evidence is unique: intangibility and ease of modification or deletion.
Risks of temporary data retention policies and automatic deletion systems.
The urgency of implementing rapid preservation measures.
Lecture 2.1: Territoriality in the Cloud Era
How cloud computing complicates traditional, geography-based legal territoriality.
The reality of decentralized data: when users, providers, and physical servers operate across multiple distinct countries.
Lecture 2.2: Sovereignty and Remote Access
The controversy surrounding unilateral remote access to foreign-stored data.
Debates over state sovereignty and disputed extraterritorial powers.
Lecture 2.3: Failure of Fast-Track Justice: Mutual Legal Assistance (MLA)
Why traditional MLA procedures fail in digital investigations (slowness, bureaucracy, and translation/approval requirements).
The danger of evidence disappearing during months-long request backlogs.
Lecture 3.1: Encryption and Anonymization
How end-to-end encryption restricts lawful access, even after device seizure.
The use of VPNs and the Tor network to hinder attribution and mask identity.
The increasing need for specialized technical forensic expertise.
Lecture 3.2: The Role of Service Providers
Private companies as the gatekeepers of digital evidence.
Managing conflicting national laws and differing corporate cooperation policies.
How providers balance data disclosure obligations against customer privacy.
Lecture 4.1: Securing vs. Disclosing Data
The distinct legal difference between data preservation (preventing deletion) and data disclosure (accessing content).
Why immediate preservation actions still require separate legal authorizations before access is granted.
Lecture 4.2: Maintaining Integrity and Chain of Custody
Mitigating the risk of data manipulation.
Essential forensic standards: forensic imaging and cryptographic hashing.
Meeting court requirements for absolute proof of authenticity and reliability.
Lecture 5.1: Privacy, Data Protection, and Judicial Oversight
How gathering digital evidence impacts fundamental privacy rights and data protection principles.
Applying the principle of proportionality to electronic search and seizure.
The mandatory requirement for strict judicial oversight.
Lecture 5.2: International Frameworks and Reforms
The Budapest Convention as an international framework for electronic evidence.
EU e-evidence reforms aimed at simplifying and speeding up cross-border cooperation.
The ongoing challenge of balancing investigative efficiency with fundamental rights.
Module Quizzes (40% total): Conceptual multiple-choice questions at the end of each module evaluating students on data volatility, encryption types, and jurisdictional conflicts.
Case Study Analysis (30%): A written assignment evaluating a hypothetical cross-border fraud case. Students must outline the steps required to rapidly preserve cloud-stored data across multiple jurisdictions while maintaining a valid forensic chain of custody.
Final Exam (30%): A comprehensive exam testing knowledge of legal frameworks (e.g., Budapest Convention, MLA flaws), technical barriers (encryption, hashing), and human rights compliance (proportionality, judicial oversight).