Digital Evidence in Spanish Criminal Proceedings · Alicante · Madrid · All Spain
WhatsApp messages, device images, IP logs and cloud data now decide most contested criminal cases in Spain.
Their admissibility depends on rules that are frequently breached.
In brief. WhatsApp messages, device images and IP logs in Spanish criminal proceedings: articles 588 bis and following, chain of custody and exclusion of evidence.
At a glance
Act 13/2015 inserted a complete regime for technological investigation measures into the Criminal Procedure Act, in articles 588 bis a) to 588 octies. It applies to the interception of telephone and electronic communications, the capture of oral communications, the use of tracking devices, the recording of images in public places, the remote search of computer equipment and the examination of mass storage devices.
The regime is built on principles that the judicial authorisation must expressly satisfy: speciality, meaning the measure must relate to a specific offence and not to a general fishing exercise; suitability; exceptionality and necessity; and proportionality. The order must identify the measure, its scope, its duration, the persons affected and the officers responsible, and it must state reasons rather than reproduce a template.
Two provisions matter in almost every case. Article 588 sexies requires a specific judicial authorisation to examine the contents of a seized computer or mobile phone, separate from the authorisation to seize it. And article 588 septies allows remote searches only for a closed list of serious offences.
The evidential value of a device image depends on the integrity of the process. In practice the defence examines whether the seizure was documented with the device state recorded, whether a forensic image was taken with write-blocking, whether hash values were calculated at acquisition and verified before analysis, whether those values match in the expert report, whether the analysis was carried out on the copy rather than the original, and whether the defence was given access to the copy so that its own expert could replicate the work.
For messaging applications the questions are different. A screenshot is manipulable, an export can be edited, and a message can be attributed to an account rather than to a person. Spanish case law requires particular caution where a conversation is produced by one party in extract, and the Supreme Court has repeatedly said that when authenticity is contested the party relying on the message must prove it, typically through a forensic report on the device or through the metadata.
Where an irregularity is established, article 11.1 of the Judiciary Act excludes unlawfully obtained evidence and, subject to the connection of unlawfulness doctrine, the evidence derived from it.
Victims and companies frequently hold the key evidence and destroy its value by handling it badly. The practical rules are to stop using the device or account concerned, to avoid deleting or reorganising anything, to obtain a forensic image before any internal review, to record the acquisition process, and to have the report prepared by an expert who can defend it under cross-examination.
For content hosted by third parties, such as an exchange, a platform or a mail provider, preservation requests and judicial orders are time-critical because retention periods are short. Where the provider is outside Spain, the route runs through the European Investigation Order within the EU or through mutual legal assistance elsewhere, and the request has to be drafted so that it is capable of being executed.
Digital evidence in Spain is governed both by the substantive provisions that protect data and communications, in article 197 and following of the Criminal Code, and by the procedural rules on the search of electronic devices introduced into the Criminal Procedure Act. As a rule, access to the content of a phone, computer or account requires a reasoned judicial authorisation and must respect the principle of proportionality.
These safeguards exist because a modern device holds a comprehensive picture of a person’s private life. When they are not observed, the resulting evidence is exposed to challenge, and in serious cases to exclusion from the proceedings.
The evidential value of digital material depends on being able to prove that what is presented to the court is identical to what was seized. This is done through the chain of custody and, technically, through hashing and other methods that demonstrate the data has not been altered.
A break in that chain, or the absence of a reliable record of how the data was captured and preserved, is one of the most effective lines of challenge, because it goes to the authenticity of the evidence rather than merely its interpretation.
We examine whether the search of a device or of remotely stored data was covered by a specific and reasoned judicial authorisation, whether its scope was respected, and whether the measure was proportionate to the offence under investigation. Remote searches in particular are subject to strict conditions.
Where the authorisation is generic, retrospective or exceeded in practice, the material obtained may be unusable, which can be decisive in cases that rest largely on electronic evidence.
We instruct independent forensic experts to review how the evidence was acquired and analysed, to test the attribution of activity to a particular person, and to identify technical weaknesses in the prosecution’s material.
This combination of legal and technical scrutiny is essential in matters where a conviction is built on metadata, logs or recovered files, none of which speaks for itself without a sound methodology behind it.
Messages and screenshots are among the most common forms of digital evidence, and also among the easiest to manipulate. Their evidential weight depends on being able to demonstrate their authenticity, ideally from the original device or account rather than from an isolated image.
We test whether the material presented is complete and unaltered, since a selective or edited exchange can convey a very different meaning from the full conversation.
Prosecutions often rely on an IP address, a login or location data to place a person at the centre of events. None of these, on its own, proves that a particular individual carried out the conduct, especially where devices or connections are shared.
We examine the strength of the link between the data and the accused, because the gap between a device and a person is frequently where these cases are decided.
Not all evidence is admissible simply because it exists. Material obtained in breach of fundamental rights, whether by the authorities or by a private party, may be excluded, and evidence derived from it can be tainted as well.
Where a recording or a message has been obtained unlawfully, we raise its inadmissibility, since the exclusion of key evidence can be decisive for the outcome of the case.
FAQ
Speak to a criminal lawyer
Criminal defence in English before the courts of Alicante, Madrid and the whole of Spain. Tell us what has happened and we will tell you what the real exposure is.