Where social media evidence actually lives
- On the platform, retrievable by Data Subject Access Request (DSAR) under UK GDPR Article 15, or by court-ordered disclosure directly to the platform.
- On the account holder's device, in application caches, WebKit databases, notification history and CameraRoll copies of media that was posted and then deleted.
- In device backups (iTunes, iCloud, Google One, Samsung Cloud) where the application databases and media are frequently included.
- In the URLs and unique identifiers embedded in every post — /status/12345, /p/ABC, /reel/XYZ — which can be cross-checked against the live platform even after the visible content has changed.
- In the account holder's email, which usually contains a long trail of platform notifications that survive account deletion.
Why a screenshot alone is not evidence
A screenshot is an unverified image. It carries no server-side identifier, no delivery record, no proof of authorship, and nothing to show whether the surrounding conversation has been selectively cropped. Modern editing tools produce convincing fabrications in minutes; a growing proportion of the screenshots exhibited in family and harassment proceedings are, on examination, fabricated or altered. A defensible exhibit ties the visible content to a server-side identifier, a device-side artefact or a DSAR record — ideally to all three.
In the Family Court in particular, screenshots are now treated with growing scepticism. The party that arrives with a hash-verified device extraction and a matching DSAR file is not the party the tribunal is worried about.
How a proper examination is run
- 01Preservation. The device is isolated, imaged and hashed before any content is exported. The account is instructed to be left alone — no further posts, no deletions, no password changes from that device.
- 02Device extraction. Full file system or physical extraction, targeting the platform's application container, the WebKit/Chromium caches, notification history and CameraRoll.
- 03Platform disclosure. A DSAR is filed in parallel; where the account belongs to a third party, disclosure is sought via CPR Part 31 or the criminal disclosure regime. The two sources cross-check each other.
- 04Identifier verification. Every URL, post ID and account handle exhibited is checked against the live platform to confirm ownership, timing and any subsequent edits or deletions.
- 05Reconciliation. Where both sides of a DM thread are available, the exhibits are reconciled message by message. Fabrications typically surface within an hour of this step.
- 06Reporting. A CPR Part 35 report setting out the artefacts, the identifiers, the reconciliation and — where relevant — the specific points at which the client's screenshots and the platform record diverge.
Common fabrications a proper examination detects
| Fabrication | How it is done | How it is caught |
|---|---|---|
| Fake DM screenshots | Browser dev tools or dedicated fake-generator apps | No matching /messages/ identifier on the platform; no cached copy on either device |
| Edited timestamps | Screen recorded with device clock rolled forward or back | Server-side timestamp in the DSAR does not match the exhibited screenshot |
| Impersonated handles | Account created with visually similar handle (rn vs m; ll vs II) | Account creation date on the platform post-dates the alleged messages |
| Selective cropping | Genuine message shown with responses cropped out | Full thread present in DSAR or device cache reveals context |
| Deleted-then-denied posts | Post made, screenshotted by recipient, then deleted | Cached copy in browser history or Instagram/Twitter notification email survives |
Practical steps for legal teams
- Preserve the client's device early; do not let them continue using the account casually once proceedings are contemplated.
- File a DSAR to the platform in the client's own name on day one; response times are 30 days and the clock does not stop.
- Where the account is a third party's, front-load the disclosure application; platform-side data is only preserved once a formal request has landed.
- Do not rely on a client's own export (Instagram Data Download, Twitter Archive) as the sole exhibit — it is unhashed, unverified and easily edited before it is sent to you.
- Ask the examiner to reconcile the client's exhibits against the DSAR before drafting the witness statement; contradictions surface earlier and cheaper than at trial.
Frequently asked questions
Frequently, yes. Deleted posts often persist in the account holder's device cache, in the recipient's cache, in notification emails, and in platform-side retention. A DSAR combined with a device extraction typically produces more than the client remembers posting.
Yes. UK GDPR Article 15 obliges platforms to provide the personal data they hold, within 30 days. Non-compliance can be escalated to the ICO and, in serious cases, to the courts.
By showing that no matching identifier exists on the platform, that no cached copy exists on the alleged sender's device, that the account creation date post-dates the alleged messages, or that the surrounding thread — visible in the DSAR — contains no such exchange. Rarely does a fabrication fail on all four; usually it fails on at least one.
The visible content disappears, but application databases, notification history, backup archives and platform-side metadata frequently persist. Recovery rates fall sharply once the account continues to be used, which is why early preservation matters.
Yes, in civil, criminal and family proceedings, provided the extraction and analysis meet the standards set by ACPO / NPCC guidance and CPR Part 35 (or the equivalent criminal / family rules). Poorly captured evidence — screenshots without provenance — is admissible but heavily discounted; forensically captured evidence is treated on the same footing as any other exhibit.
