body-container-line-1

Electronic Evidence In Modern Criminal Investigation: Lawful Acquisition, Preservation And Evidential Value

Feature Article Electronic Evidence In Modern Criminal Investigation: Lawful Acquisition, Preservation And Evidential Value
MON, 19 JAN 2026

Introduction
An essential component of contemporary criminal investigations is electronic evidence. Digital banking systems, internet-based communication platforms, mobile phones, and surveillance technologies all produce enormous amounts of data that can be used to connect suspects to illegal activities. In order to investigate crimes including fraud, cybercrime, corruption, transnational organized-crime, and violent crimes, Law Enforcement Agencies are increasingly depending on electronic evidence. This type of evidence is much more brittle, easy to tamper with, and frequently stored outside national borders compared to physical evidence. Therefore, its evidential value is dependent on both rigorous adherence to legal and forensic standards as well as relevancy. Ghana's legal system offers a cohesive framework through constitutional provisions, statutory enactments, and judicial interpretation, while not being governed by a single consolidated digital evidence statute. Crime is rapidly becoming sophisticated with the advent of Technology and the dynamics of crime scenes are moving from the conventional physical environment to a virtual environment. It is therefore imperative that a modern-day law enforcement officer, understands the essence of digital evidence in the conduct of his duty for the future is cyber, as predictively stated by Grimm J in Lorraine v Markel American Insurance [1], “because it can be expected that electronic evidence will constitute much, if not the most, of the evidence used in future practice or at a trial, counsel should know how to get it right on the first try”.

Definition of Electronic Evidence

According Maxwell Opoku-Agyemang [2], digital or electronic evidence maybe defined as any probative information stored or transmitted digitally and which a party to a judicial dispute may use in the trial. The National Institute of Justice [3] of the United States Department of Justice under its Office of Justice Programs, also defines digital or electronic evidence as “information stored or transmitted in binary form that may be relied on in court”. Nina Godbole & Sunit Belapure [4] further defines “electronic evidence also known digital evidence as an emerging area of forensic science dealing with the evidence found in computers and other electronic devices”. It is a combination of law and computer science aimed at enhancing criminal prosecution through the identification, extraction, analysis and preservation of digital data for evidential purposes. These definitions lays credence to the important role of electronic evidence in solving crimes and preparing case dockets for prosecutions. It also underpins the essence of collecting and processing this type of evidence in accordance with acceptable statutory provisions and internationally accepted best forensic practices. It involves, but not limited to mobile phone data (call logs, messages, multimedia, application data, etc), computer files, emails, CCTV and Surveillances systems, social media communications, online financial transaction records, GPS and location data and cloud-based records.

Electronic messages and their evidential importance.

Act 772[5] provides the foundation for legal recognition and the litmus test for the admissibility, integrity, weight and probative value of electronic data and records. In Republic v Alexander Kofi Tweneboah [6]. The Court of Appeal upheld the decision of High Court, Financial and Economic Division, Accra, in admitting the electronic evidence of the accused's email activity, his contracts entered and internet browser activities as a proof of illegally providing mobile communication services through “sim box” fraud.

The Court speaking through Gyaesayor, JA stated, “in our view, the evidence assembled by the prosecution is not fanciful but real and sufficient to support the ruling of the trial judge”.

Notwithstanding the legal recognition of electronic evidence as espoused above, The Evidence Act of Ghana [7] serves as the main foundation for the admissibility of electronic evidence and, that the test for assessing the issue of its admissibility is relevance. The Act [8] states that “no evidence is admissible except relevant evidence”. Investigators need to ensure that evidence collected or devices seized in the interest of an inquiry is relevant, material and directly connected to the case(s) under investigation. The process must not be used to justify indiscriminate seizure of electronic devices that has no link to the offence. Such conducts when reported, undermines the legal credibility of proportionality and necessity, and is likely to render the process unconstitutional and vulnerable to judicial scrutiny.

Power to Extract Electronic Evidence

The power of law enforcement officers [9] to seize, search and extract electronic evidence are grounded in statutory provisions and may be executed through Court orders, search warrant, reasonable suspicion, voluntary surrender by a party and third-party assistance [10] are usually the foundation for the lawful extraction of electronic evidence. Law enforcement officers may invoke investigatory powers to obtain subscriber information and issue of production order for subscriber information [11], interception of traffic data and issue of warrant for interception of traffic data [12], and interception of content data and issue of warrant for content data [13] through an ex parte application to the High Court.

The granting of authority to law enforcement officers to conduct this exercise does not mean any officer without the requisite knowledge and expertise can perform the extraction. It must be performed by digital forensic professionals with the necessary training using approved instruments.

The privacy of persons as enshrined in the Constitution [14] 1992, must be respected at all material times. Unauthorized access, password coercion, and informal phone searches run the danger of violating constitutional rights, destroying vital information or activating volatility for devices to self-destruct information stored on them.

Others may argue that digital evidence is transnational in nature and so the common law position that every evidence is admissible in court irrespective of how it was acquired could be used as the standard for obtaining digital evidence. This stance, affirmed by Crompton J in R v Leatham [15] that “it matters not how you get it, if you steal it even, it would be admissible in evidence”.

However, it is imperative for the Ghanaian law enforcement officer to avert his mind to the provisions of the Evidence Act under Section 51 and the declaration of the Supreme Court in the cases of Raphael Cubagee v Michael Yeboah Asare & 2 Ors [16], and Abena Pokua Ackah v Agricultural Development Bank [17] where the Court declared as inadmissible secret recordings of conversations. This decision of the Court was premised on Article 18(2) of the Constitution of Ghana, 1992, which safeguards the right to privacy.

Preservation and Chain of Custody

Due to its high volatility, electronic evidence must be preserved. Devices must be shielded from remote access, removal, and alteration after they are seized. Secure evidence storage, forensic imaging, and network isolation are examples of best practices. This idea is deeply ingrained in evidential jurisprudence even though Ghana does not have a formal chain-of-custody law for digital evidence. It's the duty and responsibility of law enforcement agencies and prosecution authorities to preserve the integrity of the evidence from the time of seizure, extraction and processing until the trial. Any inexplicable lapse in custody could cast doubt on authenticity, especially in cases where digital data is easily modified. The Electronic Transactions Act also mandates providers of wire or electronic communication service or a remote computing service on the written request of a law enforcement agency to take steps to preserve [18] evidence and other records in its possession pending the issue of a court order and without disclosing any information on the request to third parties during the period.

The admissibility and evidential weight placed on electronic evidence [19] requires that, the process of extraction and preservation be done in a manner that makes the generation of the evidence reliable, its integrity intact, the originator identified and, any other facts the court may consider relevant. In Alexander Tweneboah supra, the court in admitting the extracted evidence, rejected the accompanying report prepared by the prosecution expert witness from E-Crime Bureau because it did not fully capture the details of the electronic evidence contained in the compact disc. It can be inferred from the decision of the court that the report lacked integrity per the requirements of the Electronic Transactions Act.

According to David Selorm Hukporti, Chief Superintendent of Police (Retired) [20] Chain of Custody is defined as “the witnessed, written record of all individuals who maintained unbroken control over the items of evidence”. The Cybersecurity & Infrastructure Security Agency (CISA) [21] of the United States of America, also defines chain of custody as “the process used to track the movement and control of an asset through its lifecycle by documenting each person and organization who handles an asset, the date/time it was collected or transferred, and the purpose of the transfer”.

Complying with standard procedures for handling evidence helps establish the identity of persons involved in the preservation process, protects the evidence from alteration while ensuring its authenticity and it also helps detect chain of custody breach and inappropriate measures that are likely to affect the integrity of the evidence.

Challenges faced by law enforcement agencies

Despite the use of electronic evidence in combating crime and successfully prosecuting cases in recent times, the area is still be deviled with numerous challenges which are classified into two categories, internal and external:

Internal
Inadequate Logistical and manpower support.

Most of our law enforcement agencies are ill equipped when it comes to computer forensics, and where there are enough facilities for cyber forensic examinations, there are no enough personnel with the requisite skills and techniques to match the workload. This delay investigations and gradually erodes public confidence in the investigative bodies.

Lack of proper training.
Technology is a rapidly changing area and therefore requires constant training and capacity building of personnel involved in forensic examination of electronic devices. Knowledge gain quickly becomes obsolete if not upgraded to the demands of modern technological developments, this, if not checked will hamper the harvesting of electronic evidence in accordance with legally accepted modern standard practices.

Interference of other official duties.

Because most law enforcement officers involved in forensic examination perform other duties as and when the need arise, it places major impediments on officers to fully commit to the technical process of extracting this evidence. This is a complex exercise and officers multitasking is likely to interfere with the quality and credibility of the evidence extracted.

External
Lack procedural rules.
There are no procedural laws governing computer forensic mechanisms and technics for assessing electronic devices connected to criminal acts and investigations as our laws did not contemplate the processes used to assess computer systems. This has led to the lack of clarity over legally acceptable procedure for the collection, analysis and preservation of electronic evidence in Ghana.

There is also the issue of jurisdiction and encryption [22].

The authority of a law enforcement agency to assess electronic devices of interested parties in a criminal investigation must always be grounded in law and must never be abused, the diverse location of servers, clouds computing and other computing platforms such as Whatsapp, Telegram etc. across borders makes mockery of such authority especially where there are no correlating laws and mutual cooperation among nations. Some computing applications also come with encryptions for the protection of user's privacy which maybe difficult to decrypt without the assistance of the manufacturer or service provider.

Unwillingness of victims to cooperate.

Victims are mostly the primary source of information for criminal investigations and forms the core elements of a crime.[23] The fear of stigmatization, destruction of reputation and embarrassment concerns, particularly where it involves explicit content, prevents some victims from disclosing essential information and clues to law enforcement officers which hinders identification of digital evidence and stalls collection and preservation process. Prolonging the disclosure of vital information to investigating officers may lead to the destruction of electronic evidence due to its high volatility.

Conclusion
Electronic evidence is now essential to successful criminal investigations and prosecutions. However, legal extraction, careful maintenance, and verifiable integrity are essential to its worth. In order to ensure that electronic evidence enhances rather than compromises the administration of justice, Ghanaian law enforcement agencies must improve their forensic capabilities, upgrade their procedural safeguards, and modify evidentiary standards as digital crime continues to develop. Our Criminal and Other Offences (Procedure) Act, 1960 (Act 30), Evidence Act, and digital and cyber security laws need to be amended to embrace procedural acquisition of electronic evidence.

Basic training for law enforcement agencies must encompass good knowledge and understanding of virtual crime scene management, electronic evidence acquisition and preservation. Law enforcement officers must understand the complexities surrounding the acquisition of electronic evidence in order to responsibly harness it potential while protecting the right and liberties of people.

By Owura Kwabena Appenteng Okyere Darko
Plot 10 Block E, PV Obeng Bypass
Dichemso
Manhyia South Constituency, Kumasi

References
[1] 241 F.R.D. 534 (D. Md. May 4, 2007)
[2] Law of Evidence in Ghana (2022) p.52
[3] www.nij.ojp.gov (9 January, 2026)
[4] Cyber Security 318 (2011)
[5] Electronic Transactions Act 2008 (772) as amended, Sections 5, 6 and 7
[6] The Republic v Alexander Kofi Tweneboah [2017] DLCA4659
[7] Evidence Act 1975 NRCD 323
[8] Evidence Act 1975 NRCD 323, Section 51
[9] Electronic Transactions Act 2008 (772) as amended, Section 98
[10] Electronic Transactions Act 2008 (772) as amended, Section 99
[11] Cybersecurity Act, 2020 (Act 1038), Sections 69 and 70
[12] Cybersecurity Act, 2020 (Act 1038), Sections 71 and 72
[13] Cybersecurity Act, 2020 (Act 1038), Sections 73 and 74
[14] Article 18(2)
[15] (1861) 8 Cox CC 498 at 501
[16] [2018]DLSC141
[17] [2017]DLSC17580
[18] Electronic Transactions Act 2008 (772) as amended, Section 100
[19] Electronic Transactions Act 2008 (772) as amended, Section 7
[20] Crime Scene Investigation Manual for Investigators (2017) p.96
[21] www.cisa.gov January 9, 2026
[22] Krunoslav Antolis, The Challenges of Collecting Digital Evidence Across Borders (2022)
[23] Dr Rukhsana Siddiqua, Challenges faced by Police Officers in Investigating Cyber Crime: An Exploratory Study in Bangladesh (2024)

Frank Okyere Darko
Frank Okyere Darko, © 2026

This Author has published 4 articles on modernghana.comColumn: Frank Okyere Darko

Disclaimer: "The views expressed in this article are the author’s own and do not necessarily reflect ModernGhana official position. ModernGhana will not be responsible or liable for any inaccurate or incorrect statements in the contributions or columns here." Follow our WhatsApp channel for meaningful stories picked for your day.

Just in....
body-container-line