ACPO Good Practice Guide for Digital Evidence
Association of Chief Police Officers · March 2012 · 2012
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Superseded or dormant
Superseded, replaced or no longer being updated. The archive may still be worth reading, but do not cite it as current practice.
What it is
The UK guide that states the four ACPO principles for handling digital evidence — do not change the original data, record everything done, have a competent person do any live examination, and place responsibility for compliance on the officer in charge. Its own front matter records that ACPO agreed the revised guide for adoption by police forces in England, Wales and Northern Ireland.
Who it is for, and when
Read it for the four principles, which are short, quotable, and still the framing a UK court and most UK reports use when asking whether evidence was handled properly. It is also the cheapest way for a lawyer to learn what a defensible seizure and examination is supposed to look like, because the principles are written in a page rather than a standard.
What it does not cover
ACPO was dissolved in 2015 and no longer maintains this guide; there is no official ACPO URL left, so the copy linked here is third-party hosted, and the current UK authority is the Forensic Science Regulator's statutory Code plus College of Policing guidance. It is England, Wales and Northern Ireland only, it predates cloud and modern mobile acquisition entirely, and the principles are a framework, not a method you can validate against.
Go to the source
Open at digital-detective.net (opens in a new tab)https://www.digital-detective.net/digital-forensics-documents/ACPO_Good_Practice_Guide_for_Digital_Evidence_v5.pdf
Details
- Type
- Standard or guidance
- Written for
- Working examinerLawyers and courtsNew to the fieldWorking examiner, Lawyers and courts, New to the field
- Publisher
- Association of Chief Police Officers
- Version verified
- March 2012
- Year
- 2012
- Topics
- evidence-handling, chain-of-custody, uk-practice, first-responder, legal-admissibility
- Checked at source
- Standards are revised. Confirm the current revision with the publisher before citing this.
Related entries
NIJ's first-responder guide covering electronic device types and their potential evidence, on-scene tools and equipment, securing and documenting the scene, collection, and packaging, transport and storage of digital evidence, plus a chapter of considerations organised by crime category.
Two subsections of Rule 902 that let a party authenticate electronic evidence by written certification instead of live testimony: 902(13) covers a record generated by an electronic process or system that produces an accurate result, and 902(14) covers data copied from an electronic device, storage medium, or file when authenticated by a process of digital identification. Both borrow the certification and pretrial notice machinery of Rule 902(11).
A roughly 1,500-page updated treatise covering discovery and admission of electronic evidence against federal and state rules and case law, in eight chapters, with companion Best Practices Guides including an information technology primer for lawyers.
A law review article by a federal judge who writes extensively on digital evidence, the Reporter to the Advisory Committee on Evidence Rules, and a leading evidence practitioner, written as Rules 902(13) and 902(14) were being adopted. It works through the authentication routes for electronic evidence and explains what the new self-authentication provisions were designed to do.
Investigation in cloud environments using native tooling and logs alongside conventional forensic technique: AWS, Azure and Google Cloud, then Microsoft 365, Google Workspace and containerised environments including Kubernetes, with attention to which logs must be enabled before an incident to be available after one.