Use this when a phone, laptop, account or other device has been requested, searched, seized or returned, or when family is tempted to change an account after learning of an investigation.

1. Identify physical custody

Authority, family, employer, third party or unknown. Record time and receipt before remote action.

2. Name what happened

Seized, viewed, copied/imaged, cloud accessed or access requested are different events.

3. Identify controlling jurisdiction

Riley is U.S. law; PACE is England-and-Wales law. Other jurisdictions need their own sources.

4. Preserve asserted authority

Keep warrants/orders/receipts and record issuing authority, date, scope, device/account and data described.

5. Freeze destructive changes

Pause wipe, factory reset, message deletion, cloud deletion and log clearing until the legal/security plan is clear.

6. Separate cybersecurity emergency

Active fraud or compromised credentials may require action; coordinate counsel and competent security support rather than panic wiping.

7. Determine ownership

Personal and company-owned devices create different authority, privacy and corporate-record issues.

8. Write the exact access request

Unlock, PIN/password, biometric, consent, app, cloud or export? Ask local counsel about the exact request.

9. Restore life through a separate route

Use replacement devices or carefully documented recovery where appropriate instead of altering the evidence-sensitive device.

10. Preserve the inventory

Keep device description, identifiers already known, accessories, authority, time and return instructions.

11. Preserve message context

Keep participants, timestamps, surrounding conversation, attachments, export method and translation separately.

12. Flag cross-border cloud data

Person, device, provider and storage can span countries; specialist advice may be needed.

13. Flag privileged/third-party data

Lawyer communications, medical and customer data should be surfaced to counsel without family rummaging through the device.

14. Handle returned devices deliberately

Document condition and ask whether the device remains evidentially or technically relevant before resetting.

15. Document existing backups

Provider, last known time, account owner and sync status should be recorded before creating a new backup.

16. Look for short-lived records

CCTV, access logs, hotel/delivery or company logs can expire; use proper preservation channels through counsel if needed.

17. Decide whether an expert is needed

Forensic imaging, malware review, recovery and security response are different tasks; define the task before hiring.

18. Log every handoff

From, to, local time, device, condition, accessories and reason.

19. Record approved account changes

If passwords, sessions or devices change, record what, when, why and who authorized it.

Continue / pause rule

Inventory, documentation and non-destructive preservation can usually proceed while legal questions are being answered. Reset, deletion, credential disclosure and forensic manipulation deserve a hard pause because they can permanently change data or legal options.

Digital law changes with jurisdiction, statutes, cases and technology. The checklist controls process; it does not decide warrant validity, compelled access or evidentiary remedies.

Step 16 — Document existing backups before creating new ones

Record backup provider, last known backup time, account owner, device scope and whether automatic synchronization is active. A new full sync can change timestamps and create extra copies.

If evidence sensitivity is possible, ask whether creating the new backup is actually necessary now.

Step 17 — Identify short-lived third-party records

CCTV, building-access logs, hotel records, delivery records, ride history and corporate system logs may expire under normal retention policies.

If counsel believes preservation is appropriate, identify the exact source and date range and use the proper formal channel. Do not rely on a screenshot of a portal if the underlying record may disappear.

Step 18 — Decide whether you need a specialist, and which one

A forensic image, malware review, password/account recovery and corporate incident response are different services.

Define the task before hiring: preserve / examine / recover / secure / explain. The wrong specialist can unintentionally alter the very data the family is trying to protect.

Step 19 — Log every physical handoff

When a device moves from family to lawyer, lawyer to expert, employer to counsel or authority back to the person, record:

from / to / local time / device / physical condition / accessories / reason

This simple log is not a formal forensic chain of custody, but it prevents basic uncertainty about who had the device and when.

Step 20 — Record every approved account change

If counsel approves a password reset, session revocation, new phone, account recovery or other security action, record what changed, when, why and who authorized it.

Later, the family can distinguish legitimate security maintenance from unexplained alteration.

Step 21 — Are you confusing access with ownership?

Knowing a password does not automatically mean the family owns the account or has authority to change it. Shared family services, employer systems and the detained person’s private accounts may be governed by contracts or law.

Before acting, identify the account owner, authorized users and the operational reason for access.

Step 22 — Is the device full of privileged or third-party data?

If lawyer communications, medical information, employer/customer data or another person’s accounts are likely present, flag the categories to counsel. Do not browse the device to catalogue everything unless instructed.

The handling method may matter as much as the content.

Step 23 — Is a returned device still evidence-sensitive?

Record return condition and ask whether ordinary use, reset or disposal could affect the case. A returned device may still need expert review or preservation.

Use a replacement device for ordinary life if that is the safest workable path.

Step 24 — Are source dates being recorded?

Digital-law guidance ages quickly. In the working file, record jurisdiction, decision/publication date where available and last-checked date for legal sources.

That makes stale internet advice easier to identify later.

Step 25 — What is the safest useful action right now?

Choose one action only: preserve a receipt, call counsel, secure an actually compromised account using an approved method, obtain a replacement phone, ask counsel about third-party preservation, or deliberately do nothing until authority is clarified.

“Do nothing yet” can be an active risk-control decision when the alternative is an irreversible guess.

Step 26 — Separate security copies from forensic copies

If data is exported for ordinary security, label the method and purpose. Do not later describe a convenience export as a forensic image. If a specialist makes a forensic copy, preserve it under the specialist’s process rather than using it as the family browsing copy.

Step 27 — Log provider-side actions

When an authorized password recovery, preservation request, data export or session revocation occurs, record provider, account, date, confirmation and result. Cloud changes can matter even when nobody touched the physical phone.

Step 28 — Review shared-device ownership

If several people use the same computer or tablet, identify normal users and account owners before anyone searches or reorganizes data. Physical possession does not automatically answer privacy or legal authority questions.

Step 29 — Close the checklist with a state snapshot

At the end of the review, write one line describing the device/account state: who holds it, whether it is powered, last known backup, active security risk, outstanding legal request and next authorized action.

That snapshot becomes the comparison point for the next event.

Bottom line

Open the digital-device checklist again after each new warrant/order, provider request, security incident, device handoff or return. Technical state changes can alter the safest next action.

General educational information only, not legal advice.

Related Reading

Sources and Jurisdiction Boundaries