Data Is Not Evidence: A Glossary of What Holds Digital Evidence Up
Screenshot, file, timestamp, location: the reader calls all of it "evidence," while the law has a separate name for each one. Five of those names are defined by statute. The rest are forensic vocabulary. Knowing which is which is what separates what you present from what actually holds up.

▸In this article
Someone realizes they have been scammed, screenshots the conversation, sends it to a friend, and breathes easier: the evidence is safe.
What was saved is the data. The time the message arrived, the device it came from, the number that sent it, and the record the carrier kept of the connection were all left behind. And those are precisely what would have held that data up on the day somebody challenged it.
This newsroom has already written about what to preserve in the first hours, and said there that it amounted to chain of custody "without the vocabulary." This piece is the vocabulary. Thirteen terms, with three questions for each: what it is, why it matters for evidence, and who defines it.
The third question is the interesting one. For each word on the list, either the definition sits in a statute — with a retention period, a responsible party, and a consequence for failing to comply — or it is a technical term whose evidentiary value depends on what forensic examination can demonstrate about it. Metadata, the word that gives this series its name, belongs to the second group.
Thirteen terms
The order runs from what the reader thinks is evidence to what actually holds it up.
| term | what it is | why it matters for evidence |
|---|---|---|
| Data | The content itself: the message, the photo, the amount, the name. It is on the screen, in the file, on the statement. | It is what the reader thinks the evidence is. On its own, it is the easiest thing to fabricate and the hardest to date. |
| Screenshot | A picture of what the screen was showing at the moment someone pressed the button. | It captures the data and discards everything that would have held it up. It is the weakest form on this list. |
| Metadata | Information about the data: when it was created and modified, with which tool, on which device, where. It lives inside the file, in the system that stores it, and in the service that carried it. | It is the record nobody asked for. Whoever fabricates the data rarely remembers to fabricate metadata consistent with it. |
| EXIF | The metadata standard embedded in photographs: device model, date, camera settings and, when the device records it, the coordinates. | A phone photo carries more than the image. Forwarding it through a messaging app recompresses the file and strips out what it was carrying. |
| Timestamp | The time a system recorded, not the time a user reported. There is one in every file, every access log, every message header. | The clock on a user's device can be adjusted. A third party's system clock cannot. "Date and time" is literally what the law requires providers to retain. |
| Geolocation | Where the data says it was. It can be the coordinates written into a photo, the carrier cell that served the device, or the IP address the provider assigned. | Three different levels of precision and three different owners. The user can edit the first; the other two, no. |
| Registration data | What a person supplied when opening the account or the service: name, parentage, address. It is what the financial sector calls onboarding, or KYC, although the full customer file is far larger than this. | It is what a simple official request produces: the law gives police and prosecutors access to "personal identification, parentage and address" without a court order, from banks, carriers, providers, and card issuers. The rest of the file, no. |
| Log, or record | What a service notes about its own use: who connected, from where, when, for how long. The connection provider retains it for one year; the application provider, for six months. | It is the piece the subject of the investigation does not control, and the one that only comes out with a court order. Linking the log to the registration data, so as to say who was behind an IP address, is exactly what the Supremo Tribunal Federal (STF) is currently deciding. |
| Artifact | What a system leaves behind as a side effect of working: cache, history, thumbnails, indexes. It exists on any device and in any service. | The user does not know it is there, so they neither delete it nor fabricate it. It is where forensic examination finds what the data concealed. |
| Hash | A mathematical fingerprint of the file. It changes entirely if a single bit changes. It shows up in expert reports, in notarial certifications, and in every block of a blockchain. | It proves that what is in the report is what was collected. It is the seal of the chain of custody in digital media. |
| Trace evidence | "Any object or raw material, visible or latent, observed or collected, that relates to the criminal offense." It is the term the law applies to everything above once it enters criminal proceedings. | "Latent" is the word that takes in metadata and artifacts: what cannot be seen, but is there. |
| Chain of custody | "The set of all procedures used to maintain and document the chronological history of the trace evidence," from recognition to disposal. The law names ten stages. | It is what makes a correlation hold up. Without it, the best metadata is just another piece of data. |
| Circumstantial evidence (indício) | In the statute, "the known and proven circumstance which, being related to the fact, allows one to conclude, by induction, that one or more other circumstances exist." It is the name the law gives to what a correlation produces. | It is not proof; it is what allows a conclusion. A piece of metadata is a proven circumstance; what it allows one to infer about the fact is indício. And art. 155 says the judge may not decide solely on what the investigation gathered. |
The definitions of trace evidence and chain of custody are quoted from the Código de Processo Penal, art. 158-A, as enacted by Lei 13.964/2019; the definition of circumstantial evidence, from art. 239 of the same code. The narrow definition of registration data — "personal identification, parentage and address" — appears in art. 17-B of Lei 9.613/1998 and in art. 10, § 3, of the Marco Civil.
Updated 12 September 2026: the thirteenth term, indício, was added after legal review.
What the law defines, and what it does not
Of the thirteen terms in the table, five are defined by statute. A sixth, personal data, is not on the list, but the law does define it, and it is through that definition that metadata falls under the LGPD regime.
Trace evidence and chain of custody appear in art. 158-A of the Código de Processo Penal, inserted in 2019. The following article describes the ten stages of the chain, from recognition to disposal, and those stages carry concrete requirements: individually numbered seals, a record of name, date and purpose each time a seal is broken, a report produced by a qualified examiner.
Circumstantial evidence (indício) sits in art. 239 of the same code, in a chapter of its own: the proven circumstance that, "by induction," allows another to be concluded. It is the statute's word for the outcome of a correlation. And art. 155, as amended by Lei 11.690/2008, says what circumstantial evidence cannot do on its own: the judge may not base the decision "exclusively on the informational elements gathered during the investigation," save for precautionary, non-repeatable and anticipated evidence.
Records are defined in the Marco Civil da Internet, art. 5, in two varieties. A connection record is "the set of information concerning the date and time of the start and end of an internet connection, its duration and the IP address used by the terminal to send and receive data packets." An application access record is the "date and time of use of a given internet application from a given IP address." The first is retained for one year; the second, for six months. And art. 10, § 1, states how they are obtained: only "by court order."
Registration data appears in two statutes, with identical content. The Marco Civil, art. 10, § 3, places outside the judicial reserve "registration data indicating personal identification, parentage and address." Lei 9.613/1998, art. 17-B, says from whom it may be requested: police and prosecutors have access to those three items "regardless of judicial authorization" when they are held "by the Electoral Justice system, telephone companies, financial institutions, internet providers and credit card administrators." The customer file a bank calls KYC contains identity documents, a photo, income, and source of funds. None of that is in the trio.
Personal data is defined in the Lei Geral de Proteção de Dados (LGPD), art. 5: "information relating to an identified or identifiable natural person." On the plain wording of the provision, metadata that identifies someone — coordinates written into a photo, or the IP address in a connection record — is personal data.
The other eight have no definition in Brazilian law: the data itself, metadata, EXIF, timestamp, artifact, hash, geolocation coordinates, and screenshot. They are technical or forensic vocabulary. That does not make them less useful. It changes the way they carry weight: a Marco Civil record counts because the law obliges someone to retain it and specifies how it is obtained; a hash counts because an examiner can recompute it and demonstrate that it matches.
Metadata, the subject of this series, belongs to the second group. The law does not define it. It reaches metadata indirectly: when it identifies someone, it is personal data; when it enters criminal proceedings, it is trace evidence.
The same record, two statutes
There is a consequence here that usually goes unnoticed.
The Lei Geral de Proteção de Dados states, in art. 4, that it does not apply to data processing "carried out for the exclusive purposes of" public safety, national defense, state security, or "activities of investigation and prosecution of criminal offenses." Paragraph 1 of the same article promises that such processing "shall be governed by specific legislation," which must observe due process, the general principles of data protection, and the rights of the data subject. As of the date of this article, that specific statute has not been enacted.
The upshot is that the same record lives under two regimes. While it sits with the provider, it is personal data protected by the LGPD, and the Marco Civil determines how long it is retained and to whom it may be handed over. When an authority requisitions it for an investigation, it leaves the reach of the LGPD and enters that of the Código de Processo Penal, with the chain of custody and the guarantees of the Constitution.
Protection does not end when a file becomes evidence. It changes statutes.
And the boundary between the two regimes is, at this moment, before the courts. In Ação Declaratória de Constitucionalidade (ADC) 91, the Supremo Tribunal Federal (STF) is considering whether identifying a user by correlating registration data with connection records requires a court order. The rapporteur, Justice Cristiano Zanin, voted in December 2025 to uphold the constitutionality of art. 10, § 1, of the Marco Civil, with an interpretation in conformity with the Constitution and the holding that such correlation "requires specific judicial authorization," save for situations of "imminent danger to legal interests of high value," subject to subsequent judicial review. Justice Dias Toffoli requested additional time to review the case, returned it in March 2026 with reservations about the exception and about the modulation of effects, and Justice Flávio Dino brought the matter to the full bench in person. On 27 August 2026, the rapporteur reaffirmed his vote, Toffoli concurred, and the proceedings were suspended.
Where each one lives
Every term in the table has a location, and the location determines who answers for it. A photo's metadata is inside the file, with whoever holds the file. The date the file was saved is in the system that stores it. The record that it crossed the internet is with the service that carried it. Three layers, three owners, three legal regimes for reaching each one. That is the subject of the next chapter.
In one line
A piece of data on its own proves nothing. What proves something is the correlation between the data and what was recorded about it without anyone asking, and that correlation only holds up when you know where each piece came from and that it has not changed since.
Sources
- Código de Processo Penal — arts. 158-A to 158-F, inserted by Lei nº 13.964 of 24 December 2019; art. 239, circumstantial evidence; art. 155, as amended by Lei nº 11.690 of 2008
- Marco Civil da Internet — Lei nº 12.965 of 23 April 2014, arts. 5, 10, 13 and 15
- Lei Geral de Proteção de Dados — Lei nº 13.709 of 14 August 2018, arts. 4, 5 and 12
- Anti-Money Laundering Act — Lei nº 9.613 of 3 March 1998, art. 17-B, inserted by Lei nº 12.683 of 2012
- Supremo Tribunal Federal (STF) — Ação Declaratória de Constitucionalidade (ADC) 91, case docket, certified records of the sessions of 12 December 2025, 6–13 March 2026 and 27 August 2026
- CyberX — The first hours: what to preserve once the fraud has already happened
About the author

Robert F.
request a secure channelRobert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.
He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.
In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about a case we work on, clients, matters under judicial secrecy, or operational detail that would compromise an investigation in progress — ours or anyone else's. A third party's case enters through the public official act, and through what it teaches, not through what it exposed.
Related reading
CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. This content is informational and does not constitute legal advice.
how we write →Source: https://cyberx.to/en/analysis/data-is-not-evidence-a-glossary-of-what-holds-digital-evidence-up
Retrieved on