Expert advice
Digital Evidence in Polish Criminal Cases: Admissibility
26.09.2026
Digital evidence is information of evidential value stored, processed or transmitted in electronic form, including data from mobile phones, computers, cloud accounts, email servers, CCTV systems, vehicle telematics and social media platforms. In a digital evidence criminal case Poland context, its admissibility depends not only on what the data shows, but also on how it was obtained, secured, documented and presented before the court.
Electronic evidence is central to investigations concerning fraud, corruption, money laundering, cybercrime, employee misconduct and offences involving company assets. It may establish communication between suspects, identify the flow of funds, confirm access to IT systems or reconstruct activity on a device. However, poor evidence handling can create procedural disputes, weaken the evidential value of data and expose a business to wider reputational or operational risks.
How Polish criminal procedure approaches electronic evidence
The Polish Code of Criminal Procedure does not contain one separate and exhaustive definition of electronic evidence. Digital material is assessed under general rules of evidence, including the principle that all evidence relevant to determining the truth may be admitted unless the law provides otherwise.
Under Article 167 of the Code of Criminal Procedure, evidence is taken at the request of the parties or ex officio. Article 168 provides that evidence is inadmissible where it was obtained through a prohibited act, subject to the specific rule in Article 168a. The court assesses evidence freely, taking account of logic, experience and the entire body of material collected in the case, pursuant to Article 7 of the Code of Criminal Procedure. [1]
For businesses, this means that data may be formally admitted but still have limited practical value if its origin, completeness or integrity cannot be demonstrated. A screenshot without metadata, a forwarded email without original headers, or a copied file without a documented chain of custody may be challenged by the defence.
Admissibility of digital evidence in Polish criminal cases
The key question is usually whether the electronic evidence was obtained lawfully and whether its reliability can be verified. Courts may examine, in particular:
- the legal basis for obtaining or securing the data;
- whether the authority had the required judicial or prosecutorial authorisation;
- the scope of the search, seizure or data request;
- whether the evidence was protected from alteration, deletion or unauthorised access;
- whether a forensic copy was created and properly documented;
- whether the defence can review and challenge the material.
Electronic evidence obtained during a search may be secured under the rules governing searches and seizure of items, particularly Articles 217-236 of the Code of Criminal Procedure. A computer, phone, external drive or server data may constitute an “item” relevant to the proceedings. In practice, the seizure protocol, device identification details, hash values and forensic imaging records may later become important in court.
Article 168a and unlawfully obtained digital evidence
Article 168a of the Code of Criminal Procedure is particularly significant in disputes over evidence obtained irregularly. It provides that evidence cannot be considered inadmissible solely because it was obtained in breach of procedural rules or through a prohibited act.
There are, however, statutory exceptions where the evidence was obtained by a public official acting in the course of official duties, or on that official’s order, as a result of:
- homicide;
- intentional causing of bodily harm;
- deprivation of liberty.
These exceptions should be read precisely. Article 168a does not mean that every unlawfully obtained file, recording or message will automatically be treated as reliable or decisive. The method of obtaining evidence can still affect its credibility, the assessment of procedural fairness and potential liability of persons involved in its acquisition. [1]
Private recordings, emails and employee data
In Polish criminal proceedings, material provided by a private person, such as a recording, screenshot, chat history or email archive, is not automatically excluded merely because it was obtained without the other person’s knowledge. Its admissibility and evidential weight depend on the factual circumstances.
A secretly recorded conversation may raise issues relating to privacy, personal rights or the criminal offence of unlawful interception of communications under Article 267 of the Criminal Code. The legal assessment differs where the recording was made by a participant in the conversation and where it was obtained through interception by an outsider. The court may also examine whether the material was edited, incomplete or taken out of context. [2]
For employers, access to employee communications requires particular caution. Monitoring must comply with the Labour Code, including Articles 222 and 223, as well as data protection rules. Evidence collected through internal monitoring may be useful in a criminal case, but an unlawful monitoring system can generate separate employment, privacy and regulatory exposure. [3]
Computer forensics and the chain of custody
Computer forensics is often decisive where the case concerns deleted files, malware, unauthorised access, manipulated accounting records or large volumes of business communications. A forensic examination should preserve original data and allow experts to explain how a conclusion was reached.
Important safeguards include:
- creating a verified forensic image rather than working on the original device;
- recording hash values to demonstrate file integrity;
- documenting each transfer, access event and examination step;
- separating relevant business data from legally privileged or personal information;
- using an appropriately qualified expert where specialist analysis is required.
These steps matter because digital data is easy to copy but also easy to alter. In a corporate investigation, an unstructured internal review may overwrite logs, modify file access dates or compromise the ability to show that the material is authentic. Early preservation measures may therefore be more valuable than an extensive but delayed review.
Cross-border electronic evidence and EU mechanisms
Many criminal cases involve service providers located outside Poland or data stored across several jurisdictions. Traditional mutual legal assistance can be slow, especially where authorities seek subscriber information, traffic data or content from foreign platforms.
The EU e-Evidence Package introduces European Production Orders and European Preservation Orders for specified categories of electronic data. Regulation (EU) 2023/1543 is intended to improve cross-border access to electronic evidence in criminal proceedings and applies from 18 August 2026. Its practical impact will depend on the type of data sought, the location of the service provider and the procedural safeguards applicable in the particular case. [4]
Companies facing a foreign evidence request should assess the request promptly. Relevant issues include data preservation obligations, confidentiality, legal privilege, GDPR requirements, trade secrets and the risk of obstructing proceedings through deletion or alteration of records.
Practical steps for companies facing a digital evidence issue
When a suspected offence involves company systems or employee devices, management should avoid informal evidence gathering. A defensible response usually requires coordinated criminal, employment, compliance and data protection analysis.
- Preserve potentially relevant data without altering original records.
- Limit access to the investigation material and document all actions.
- Assess whether internal monitoring and data collection were lawful.
- Identify whether notification to law enforcement is required or strategically justified.
- Secure legal privilege and confidential business information before disclosure.
- Consider an independent forensic review where manipulation or cybercrime is suspected.
Kopeć & Zaborowski (KKZ) advises businesses and individuals on criminal investigations, cybercrime matters, internal investigations and the protection of digital material. Further information is available in the law firm’s overview of cybercrime legal services and its guide to the EU e-Evidence Package in Polish criminal trials.
This is informational material, not legal advice. The admissibility of electronic evidence depends on the factual circumstances, the method of collection and the stage of proceedings.
Where a criminal matter, including an allegation concerning cybercrime, involves phones, messages, recordings or other electronic material, it may be appropriate to consult the matter with a criminal lawyer. Early legal assessment can help identify possible procedural steps and evidence-preservation measures.
FAQ – Digital Evidence in Polish Criminal Cases
Is digital evidence admissible in Polish criminal proceedings?
Yes. Digital evidence may be admitted if it is relevant to the case and its origin, integrity and method of acquisition can be assessed. The court determines its evidential value in the context of all available evidence.
Can screenshots be used as evidence in a Polish criminal case?
Yes, but screenshots are usually less reliable than original data. Their value may depend on whether the source device, account data, metadata, message history or other corroborating evidence is available.
Can police seize a company laptop or employee phone?
Yes, where statutory conditions for search and seizure are met and the device may contain evidence relevant to the proceedings. The scope and legality of the seizure can be challenged depending on the circumstances.
Are secretly recorded conversations admissible in Poland?
They may be admitted, but the legal assessment depends on who made the recording, how it was obtained and whether privacy or criminal-law rules were breached. Admissibility does not automatically determine reliability or legality.
What is the importance of hash values in computer forensics?
Hash values help demonstrate that a forensic copy of data has not changed. They are an important technical tool for confirming integrity and supporting a documented chain of custody.
Does Article 168a make all illegally obtained electronic evidence admissible?
No. Article 168a prevents exclusion solely for specified irregularities, subject to its statutory exceptions. The court may still assess the evidence critically, and the collection method may create separate legal consequences.
Bibliography
- [1] Act of 6 June 1997 – Code of Criminal Procedure, consolidated text: Journal of Laws of 2024, item 37, in particular Articles 7, 167, 168, 168a and 217-236.
- [2] Act of 6 June 1997 – Criminal Code, consolidated text: Journal of Laws of 2024, item 17, in particular Article 267.
- [3] Act of 26 June 1974 – Labour Code, consolidated text: Journal of Laws of 2025, item 277, in particular Articles 222 and 223.
- [4] Regulation (EU) 2023/1543 of the European Parliament and of the Council of 12 July 2023 on European Production Orders and European Preservation Orders for electronic evidence in criminal proceedings and for the execution of custodial sentences following criminal proceedings.
- [5] Directive (EU) 2023/1544 of the European Parliament and of the Council of 12 July 2023 laying down harmonised rules on the designation of designated establishments and the appointment of legal representatives for the purpose of gathering electronic evidence in criminal proceedings.
Need help?
Expert advice
Surveillance and Wiretapping in Poland: Defense Strategies
Surveillance and Wiretapping in Poland: Defense StrategiesSIM Swapping and Phone Fraud in Poland: Criminal Threat
SIM Swapping and Phone Fraud in Poland: Criminal ThreatCross-Border Cybercrime: Poland’s International Cooperation
Cross-Border Cybercrime: Poland’s International CooperationHow can
we help you?
the experts