Most workplace misconduct now leaves a digital trail, which is good news for investigators and a trap for the untrained. Digital evidence is easy to destroy accidentally, easy to collect unlawfully, and easy to misread — and a single mishandled collection can taint an otherwise sound investigation.
Quick answer: Preserve immediately, collect through IT with a documented process, restrict scope to what is relevant, and understand the privacy limits that apply to personal devices and accounts. Employer-owned systems are generally accessible with a clear policy; personal accounts and devices largely are not.
Preservation is urgent because retention is automatic and unforgiving. Systems overwrite video, purge deleted items, and roll off logs on schedules nobody remembers until the evidence is gone.
Issue a preservation instruction to IT on day one covering:
Suspend automatic deletion for the affected custodians. Document the instruction, who received it, and when. If litigation is reasonably anticipated, issue a formal legal hold — spoliation sanctions can be more damaging than the underlying claim.
|
Source |
Generally Accessible? |
Conditions |
|
Company email |
Yes |
With a clear policy stating no expectation of privacy |
|
Company chat platforms |
Yes |
Same — ensure the policy covers DMs, which employees often assume are private |
|
Company devices |
Yes |
Policy plus, ideally, acknowledgment at issuance |
|
Company network and file shares |
Yes |
Restrict scope to what is relevant |
|
Video in common work areas |
Usually |
Notice may be required; audio recording is separately restricted in many states |
|
Personal email accessed on a company device |
Complicated |
Accessing personal accounts — even from a company device — can violate federal and state computer and communications statutes |
|
Personal devices (BYOD) |
Limited |
Depends on the BYOD agreement; generally limited to company data |
|
Public social media |
Yes |
Public content only |
|
Private social media |
No |
Several states prohibit requesting credentials or requiring access |
|
Personal text messages |
Only if voluntarily provided |
Employees may share their own; you cannot compel access to a personal device |
Collection is the mechanical part. Interpretation is where investigations go wrong.
Direct messages are the most productive source in most modern investigations and the one employees most often assume is private. Confirm your policy explicitly covers DMs. Retention settings vary by workspace and channel, so check retention configuration before assuming history exists. Note that some platforms allow message editing and deletion, and edit history may or may not be recoverable depending on plan and settings.
Recordings, chat logs, and transcripts may all exist. Recording consent requirements vary by state. Check whether recording was enabled and whether participants were notified.
Employees frequently use personal messaging apps on company devices. Whether you may access that content depends on your policy and applicable law — and even where technically accessible, accessing a personal account may violate communications statutes. Consult counsel.
Public content may be reviewed. Document what you viewed and when, with the URL and a dated capture. Do not friend, follow, or otherwise gain access to restricted content, and do not use a third party to do it.
Your ability to access company systems rests on your policy. Confirm it:
A policy that does not mention direct messages is the most common gap, because it is where the evidence usually is.
Generally yes, with a clear policy stating no expectation of privacy. Restrict scope to what is relevant and route collection through IT.
Generally no. Accessing a personal account can violate federal and state statutes even when the account is open on a company device.
Only with voluntary consent, and only within the scope of that consent. Do not compel access.
It is a starting point. Where the content is material, obtain it from the system with metadata intact.
Document the deletion and the timing. Deletion after notice may itself be a policy violation and, if litigation is anticipated, spoliation.
Preserve immediately, collect through IT, stay within legal limits, and read the whole thread. Those four habits prevent nearly every digital evidence problem.
The Internal Investigations Certificate Program covers evidence collection and handling. For complex matters involving forensic evidence, see the Advanced Internal Investigations Certificate Program.
👉 See the Workplace Investigation Training Program →
Additional resources: Documenting Evidence From an Internal Investigation | Workplace Investigations FAQs | Data Security Best Practices
Recommended In-Person Seminars