Nobody Holds the Whole Metadata
A photo carries one date inside it, the device records another, and the service it passed through logs a third. Each belongs to a different owner, and each owner answers to a different law. That is why serious digital evidence is always correlation — and why serious correlation leaves a judicial paper trail.

▸In this article
A photo sent during a scam carries three dates. The one the camera wrote inside the file. The one the device recorded when it saved it. The one the messaging service logged when it carried it. Three dates, three owners, and none of them holds the other two.
The previous installment in this series, the glossary of digital evidence, set out what each term means and who defines it. This one sets out where each one lives, by class of location, and what opens the door to each house. The question changes: it is no longer "what is it," but "who holds it, and what does it cost to ask."
Layer 1: inside the file
Who holds it: whoever holds the file. What it holds: whatever the file itself carries. In a photo, the EXIF standard: device model, date, camera settings and, when the device records it, the coordinates. In a document, who created it, when it was modified, and with which program.
What opens the door: possession. If the victim holds the file, the victim hands it over, and what determines the value of what was handed over is the preserved original, with the date it was secured and a mathematical fingerprint any examiner can verify later. This is what The first hours taught without the vocabulary and the glossary named: chain of custody, art. 158-A of the Código de Processo Penal. If the file is held by the person under investigation, the door is a different one — and that is the next layer.
One sentence will do on what does not get written here: saying that a photo carries coordinates is a principle; saying where the traces of editing are found is a map. This piece stays with the principle.
Layer 2: the system that stores it
Who holds it: whoever controls the device, or the cloud account. What it holds: the dates the system records on its own initiative, the artifacts it leaves behind as it runs, the copy that went up to the cloud without anyone asking.
What opens the door, when the device belongs to the person under investigation, is a search and seizure warrant. The 1941 Code authorizes a residential search "where well-founded reasons so warrant," among other purposes, to "discover objects necessary as evidence" and "gather any element of proof," under a warrant stating "the grounds and the purposes of the measure." The law speaks of things, homes and persons. It says nothing about content.
The question of content was answered by the Supremo Tribunal Federal (STF) in June 2025, under Tema 977 of general repercussion. The holding separates the two doors precisely. Seizing the device, under art. 6 of the Code or in flagrante, "is not subject to judicial reservation." Reading what is inside a seized device "shall be conditioned on the express and free consent of the data subject or on a prior judicial decision," grounded in concrete elements and narrowly framed. A device found by chance is the exception: access solely to determine ownership and authorship "does not depend on consent or on a prior judicial decision, provided it is justified afterwards." And the holding uses this series' own word: police "may take the measures necessary for the preservation of the data and metadata contained in the device" before the order, justifying it later. Preserving is not reading. It is chain of custody as stated by the Supreme Court.
The holding names art. 6 and flagrante. On a reading of that wording, the same applies to a device seized under an art. 240 warrant: the rule is about access to content, not about the form of the seizure. The holding has prospective effects and pending motions for clarification, referred to the Procuradoria-Geral da República since June 2026. The Superior Tribunal de Justiça (STJ) had got there first: in 2016, in RHC 51.531, it held that "without prior judicial authorization, the rifling of data and WhatsApp conversations obtained directly by the police from a mobile phone seized in flagrante is unlawful."
When what you are after sits in the cloud, the owner is the provider — and that is the next layer.
Layer 3: the service that carried it, across three counters
This is where metadata matters most, because it is the record the person under investigation does not control. And "the service" is not one counter. It is three, under three laws, and each answers differently to three different requests: subscriber data, logs and content.
The internet provider
This covers both the connectivity provider and the application operator, from e-mail to social networks. The law is the Marco Civil da Internet.
Without a judge: subscriber data reporting "personal identification, parentage and address," which an administrative authority with statutory competence may requisition (art. 10, § 3).
With a judge: the logs, both connection logs and application access logs, "standing alone or associated with personal data," only "by judicial order" (art. 10, § 1). And the content of communications, only by judicial order, "in the circumstances and in the manner established by law" (art. 10, § 2).
How long it exists: connection logs are retained for one year (art. 13); application access logs, for six months (art. 15). After that, the provider may delete them, and the law allows the authority to request longer retention (art. 13, § 2, and art. 15, § 2). This is the deadline advice the glossary left for this piece: application logs vanish in six months if nobody asks.
The frontier under judgment: correlating subscriber data with logs in order to arrive at a person is precisely the act at issue in Ação Declaratória de Constitucionalidade (ADC) 91. Under the holding proposed by the rapporteur, Justice Cristiano Zanin, that correlation "requires specific judicial authorization." The judgment is suspended, and the analysis comparing the US rule with the Marco Civil sets out the chronology.
The telecom carrier
Here the law splits in two, and a Supreme Court decision still in progress organizes both halves.
Without a judge: in ADIs 5.059 and 5.073, concerning the statute defining what a police chief may requisition, the rapporteur, Justice Dias Toffoli, voted on 27 August 2026 that the police chief and the Ministério Público may requisition directly from carriers the "subscriber data" of the line holder, "understood to mean, solely, full name, parentage and address." The separate opinion delivered in 2025 by Justice Cristiano Zanin — the same rapporteur in ADC 91 — contains the formulation that best explains where the line runs: direct requisition only for what "entails low-intensity interference with the sphere of privacy, such as access to basic subscriber data." The judgment was suspended the same day.
Without a judge, but only for certain offenses: the Código de Processo Penal opens a narrow exception. For the offenses against personal liberty it lists, and for human trafficking, the police chief and the Ministério Público may requisition subscriber data on victims and suspects directly (art. 13-A) and, in human trafficking cases, the signals that allow a victim or suspect to be located, for up to thirty days (art. 13-B). The rapporteur's 27 August opinion places within that exception cell-site location and, in human trafficking cases, call records and text message records as well, "without prior judicial control, but always subject to subsequent judicial control."
With a judge, and under seal: content. Intercepting telephone communications, "of any kind," requires a judicial order "under judicial seal" (Lei 9.296/1996, art. 1), and the statute applies equally "to the interception of the flow of communications in computer and telematic systems." It is not permitted where there are no "reasonable indications of authorship," where "the evidence can be obtained by other means," or where the offense carries only a detention penalty (art. 2). The order is valid for fifteen days, renewable once (art. 5). On the plain wording of both statutes, this covers the flow — communications in transit. A message already delivered and stored at the provider is stored content, and falls under art. 10, § 2, of the Marco Civil.
The bank and the card issuer
The rule is confidentiality. Financial institutions "shall maintain confidentiality in their asset and liability operations and in the services they provide" (Lei Complementar 105/2001, art. 1), and the list includes credit card administrators.
Without a judge: the same trio. Art. 17-B of Lei 9.613/1998 grants the police and the Ministério Público access, "regardless of judicial authorization," to subscriber data "reporting personal identification, parentage and address," held by financial institutions, carriers, providers and card administrators. The Supreme Court fixed the limit in a binding holding, in ADI 4906, in 2024: the provision is constitutional, "excluding from its scope the possibility of requisitioning any subscriber data other than those relating to personal identification, parentage and address." Motions for clarification are pending: the rapporteur voted to reject them, and the matter was taken to the in-person plenary in September 2026.
With a judge: everything else. Information "ordered by the Judiciary" is furnished "with its confidential character preserved through restricted access by the parties" (LC 105, art. 3).
What does not count as a breach of confidentiality: reporting an unlawful act to the authorities (art. 1, § 3, IV), which is the channel through which the bank raises the alarm, and the exchange of subscriber data between institutions (item I), which is the channel through which registration data circulates.
One point art. 13-A leaves open: it speaks of "registration data and information" held by any agency or company, without the trio. Whether the limit the Supreme Court fixed for art. 17-B also reaches art. 13-A is a reading this series does not yet settle.
The table
| where it is | who holds it | released without a judge | only with a judge |
|---|---|---|---|
| Inside the file | Whoever holds the file | Everything, if it is yours | Seizure, if it is someone else's |
| On the device or in the cloud | Whoever controls the device or the account | Seizure of the object; preservation of the data, justified afterwards | Access to content, absent free consent or chance discovery (Tema 977) |
| At the internet provider | Connectivity or application provider | Identification, parentage and address (art. 10, § 3) | Logs and content (art. 10, §§ 1 and 2); correlation, at issue in ADC 91 |
| At the carrier | Telecom concessionaire | Name, parentage and address; location and call records only for the offenses in arts. 13-A and 13-B, with subsequent control | Content, by interception, fifteen days renewable |
| At the bank or card issuer | Financial institution | The subscriber data trio (17-B, ADI 4906) | Operations and services (LC 105, art. 3) |
The same data, two laws, once again
While it sits with the provider, the carrier or the bank, all of this is personal data under the Lei Geral de Proteção de Dados. Once the authority requisitions it for an investigation, it leaves that statute's reach, because the law itself says it does not apply to criminal investigation and promises specific legislation that never arrived. The glossary already told that story. Here it serves a single purpose: the regime protecting the data changes its name at the door, but the door is still there.
Why correlation needs three doors
Since no single owner holds everything, any correlation capable of sustaining evidence has passed through more than one door. And the doors that require a judge leave a trail: the order, the official request, the dated response. That trail is the chain of custody of the correlation. A correlation that cannot show how it got in at each layer is just data like any other — and the rapporteur's proposed holding in ADC 91 says exactly that when it makes the correlation, rather than the data, the act requiring authorization.
In one line
Nobody holds the whole metadata. Whoever assembles the parts must show which door they came through at each one, and it is that accounting, not the data, that the law polices.
Sources
- Código de Processo Penal — arts. 6, 13-A, 13-B, 158-A and 240 to 250
- Marco Civil da Internet — Lei nº 12.965, de 23 de abril de 2014, arts. 5, 10, 13 and 15
- Interception statute — Lei nº 9.296, de 24 de julho de 1996, arts. 1, 2 and 5
- Bank secrecy — Lei Complementar nº 105, de 10 de janeiro de 2001, arts. 1 and 3
- Money Laundering Act — Lei nº 9.613, de 3 de março de 1998, art. 17-B
- Lei Geral de Proteção de Dados — Lei nº 13.709, de 14 de agosto de 2018, art. 4
- Supremo Tribunal Federal (STF) — ARE 1.042.075, Tema 977 of general repercussion, holding fixed on 25 June 2025; order on the motions for clarification of 17 June 2026
- Supremo Tribunal Federal (STF) — ADC 91, record of the session of 27 August 2026
- Supremo Tribunal Federal (STF) — ADI 5.059 and ADI 5.073, record of the session of 27 August 2026 and separate opinion of September 2025
- Supremo Tribunal Federal (STF) — ADI 4906, holding of 11 September 2024; record of the virtual session on the motions for clarification, 11 to 18 September 2026
- Superior Tribunal de Justiça (STJ) — RHC 51.531-RO, Informativo de Jurisprudência, special edition no. 18, decided on 19 April 2016
- CyberX — Data is not evidence: a glossary of what holds digital evidence together
About the author

Robert F.
request a secure channelRobert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.
He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.
In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about a case we work on, clients, matters under judicial secrecy, or operational detail that would compromise an investigation in progress — ours or anyone else's. A third party's case enters through the public official act, and through what it teaches, not through what it exposed.
Related reading
CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. This content is informational and does not constitute legal advice.
how we write →Source: https://cyberx.to/en/analysis/nobody-holds-the-whole-metadata
Retrieved on