Skip to content

September 24, 2026 · Evidence Handling Workflows

Collecting Evidence From Cloud Services

Collection of cloud-held evidence begins with determining who controls the data—the enterprise custodian or the provider—because that choice governs whether you request an export from the account owner, seek a warrant under 18 U.S.C. § 2703, or pursue both. The method matters deeply: provider export tools are optimized for user convenience, not forensic completeness, so documentation of what was exported and what was deliberately or systemically excluded is essential to the chain of custody.

Determine the Custodian and Collection Path

Collection of cloud evidence rests first on a factual and legal question: who holds the authority to produce the data? The lawful custodian is the owner, person, or enterprise with legal authority over the data. [1] This determination drives the entire collection strategy.

When an enterprise uses a cloud storage provider—such as a business using Microsoft 365, Google Workspace, or Salesforce—and the enterprise itself is not the subject of investigation, the ordinary collection path is to request an export directly from the enterprise custodian, ideally using their own credentials and the provider's native export tools. [1] This approach is often faster, requires no legal process, and preserves the chain of custody through a known actor.

The analysis changes when the custodian is the subject of investigation. When either the enterprise or the cloud provider is the subject of investigation, or when approaching the enterprise might compromise the investigation, the preferred method is to seek the data through legal process directed to the cloud service provider itself. [1] In the federal system, this typically occurs through a warrant issued under 18 U.S.C. § 2703, which permits a court to issue a warrant for records held by a cloud provider located in another district and authorizes the provider to conduct the search. [2] State and local practitioners should consult applicable statutes governing their jurisdiction.

The choice between these paths affects not only who produces the export but what legal authority must be demonstrated and what authentication evidence will later be available at trial or in discovery.

Understand the Limits of Provider Exports

Data returned by a cloud service provider's native export tools may not be as complete as if the same data had been obtained directly from the provider through legal process and formal forensic acquisition. [1] This incomplete nature deserves explicit documentation. Provider export tools are designed principally for user accessibility and recovery—a user who wishes to migrate their mail or files to another system—not for forensic completeness or the capture of system artifacts, metadata, or account administration records.

When the lawful custodian consents, or when you possess appropriate credentials and legal authority to act, use of the provider's native tools is a best practice. [1] These tools are transparent, often audited, and produce exports that can be traced back to the provider's official processes. But you must understand what they do and, critically, what they omit.

A typical mailbox export contains message bodies and attached files, but it may exclude or truncate server-side rules, delegate access logs, recoverable deleted items in an archive folder, detailed header information, or metadata about when items were moved, forwarded, or accessed. A file export may contain the current version of documents but not version history, deletion events, share permissions at the time of export, or access logs. These omissions are not errors; they are choices built into the tool. Document them explicitly.

Collect Account-Level Artifacts Separately

No export of mailbox contents or file stores will capture account-level artifacts—data that describe how the account itself is configured and used. [1] These items include login history and geographic anomalies, account settings and security configurations, delegation structures and recovery options, connected devices and mobile app authorizations, and security events flagged by the provider's own threat detection.

These artifacts must be specifically requested from the custodian or the provider. In many civil discovery contexts, parties exchange information about key custodians of electronically stored information and relevant retention policies; requirements and best practices vary by jurisdiction and court. [6] [7] [8] In federal criminal cases, the Recommendations for ESI Discovery in Federal Criminal Cases provide a framework for planning and producing ESI, including the identification of the custodians and systems from which data will be extracted. [4]

When collecting from an enterprise custodian with consent, ask for a comprehensive account configuration export—a formal report from the provider's administrative console showing all account settings, permissions, and recent activity at the moment of collection. This becomes part of your baseline.

Observe Preservation Deadlines and Provider Retention Policies

Under 18 U.S.C. § 2703(f), service providers are required to preserve data when requested by law enforcement pending further legal process. [3] However, preservation windows are finite and vary by provider and applicable law. Once you make a preservation request, the provider's clock begins running—the preservation period depends on the provider's policy, state law, and federal requirements. You must confirm your provider's retention window immediately upon matter initiation and request formal preservation in writing.

If legal process is delayed or the investigation scope expands, critical logs—authentication records, account access events, or metadata—may be overwritten by routine provider data retention cycles before collection occurs. Provider retention policies vary substantially by service type and business model. You must confirm retention windows with the provider before planning your collection and include this in your written preservation request.

Document the Export Completely

Accurate documentation of how, when, and by whom the export occurred is as important as the export itself. Your record must capture:

Method and version. Note the specific tool used (e.g., "Microsoft 365 eDiscovery export via the Compliance Portal, version [X.X.X]"), the date it was run, and by whom. If the custodian ran the export themselves, note their name, title, and the date and time they performed it.

Scope. What data types were requested and exported—mail, calendar, contacts, files, shared drives, teams, or other formats? What date range does the export cover? Were attachments included? Were deleted items included? State this explicitly.

Service provider's local time. Record the date and time of export using the service provider's recorded local time, and note the timezone. [1] Examiners should use their forensic knowledge to identify any discrepancies between the export timestamp and the metadata within the exported data, and if needed, conduct further artifact analysis. [1] If a discrepancy appears—for instance, message timestamps suggesting they were sent before the export began, or file modification dates after export completion—document the discrepancy and your investigation of it.

Operator credentials and authorization. Who executed the export, and on what authority? If done by the custodian, note their identity and method (direct provider portal login, delegated admin access, etc.). If done via legal process by the provider, note the warrant number or other legal instrument.

Manifest and exclusions. Provide an explicit accounting of what the export contains: the number of messages, files, or items; hash values if available; and the total volume in bytes or gigabytes. Explicitly state what was not exported—what was excluded by tool design or by deliberate choice. "The export includes mail from January 1, 20XX to December 31, 20XX, but excludes the Deleted Items and Archive folders, which the provider [did/did not retain at time of export]." "Shared file permissions and version history were not exported with the file export tool."

Account baseline. Capture account settings, metadata structures, and configuration at the moment of export. This becomes part of your evidence record and is critical to establishing the context of what the export contains.

If the export is large or complex—thousands of files, multiple accounts, or data spanning years—consider engaging a digital forensics examiner to verify the completeness and integrity of the export and to produce a formal collection report. This is particularly important if the evidence will be contested or if the case involves allegations that data was hidden, destroyed, or altered.

Legal Basis for Collection and Admissibility

Under the Federal Rules of Civil Procedure, electronically stored information stands on equal footing with paper documents. [5] Discovery under Rule 34 applies to information that is fixed in a tangible form and to information that is stored in a medium from which it can be retrieved and examined. [5] This means cloud-held data is discoverable; the method of collection must be appropriate to the legal authority you possess.

Authentication of cloud evidence is governed by the Federal Rules of Evidence. Evidence must be authenticated by testimony that it is what it purports to be. [9] A cloud export will typically require testimony from someone with knowledge of the account or the export process—often the custodian or the examiner who documented the collection—attesting to the accuracy of the export and the chain of custody.

Careful documentation of the collection process supports the admissibility of evidence. A court will examine how the evidence was collected, by whom, under what authority, and with what safeguards against alteration or loss. Gaps in documentation invite challenge and may limit a court's ability to rely on the evidence.

Common questions

How is data held by a cloud provider collected as evidence?
Data held by a cloud provider is collected either directly from the enterprise custodian—using the provider's native export tools and the custodian's own credentials—when the custodian consents or is not the subject of investigation, or through legal process directed to the provider when the custodian is a subject or approaching the custodian would compromise the investigation. [1] In the federal system, legal process typically takes the form of a warrant under 18 U.S.C. § 2703, which permits the provider to conduct the search on the government's behalf. [2] The choice of method affects who produces the export, what legal authority is required, and what chain-of-custody testimony will be available later.
Who is the custodian of data a provider holds?
The lawful custodian is the owner, person, or enterprise with legal authority over the data. [1] When an enterprise uses a cloud service—such as a business using Microsoft 365 or Google Workspace—the enterprise is ordinarily the custodian, even though the data is stored on the provider's servers. When determining the collection path, you must consider whether the custodian themselves is the subject of investigation, because that distinction governs whether collection is requested directly from the custodian or through legal process directed to the provider. [1]
What does a provider export leave out?
Data returned by a cloud service provider's native export tools may not be as complete as data obtained directly from the provider through legal process. [1] Provider export tools are optimized for user convenience and recovery, not forensic completeness; they typically exclude server-side rules, detailed access and deletion logs, account configuration records, connected devices and authorizations, and metadata about account administration and security events. [1] Additionally, exports often omit version history of files, deletion events, and share permissions at the time of export. These omissions must be documented as part of the chain of custody.
How long do providers keep the logs an investigation needs?
Under 18 U.S.C. § 2703(f), service providers are required to preserve data upon request by law enforcement, but preservation windows vary by provider and applicable law. [3] Retention policies differ substantially by service type and business model. You must confirm the provider's retention policy and preservation window immediately upon matter initiation and issue a written preservation request to prevent logs and metadata from being overwritten by routine data retention cycles.

Sources

  1. [1] Best Practices for Digital Evidence Acquisition, Preservation, and Analysis from Cloud Service Providers (SWGDE-23-F-004-1.1) Scientific Working Group on Digital Evidence
  2. [2] Executing Search Warrants in the Cloud FBI Law Enforcement Bulletin
  3. [3] Seeking Enterprise Customer Data Held by Cloud Service Providers Department of Justice, Computer Crime and Intellectual Property Section
  4. [4] Recommendations for ESI Discovery in Federal Criminal Cases Department of Justice, Judicial Education and Technical Working Group
  5. [5] Federal Rules of Civil Procedure Rule 34 (Producing Documents, Electronically Stored Information, and Tangible Things) US Courts, Cornell Law
  6. [6] ESI Principles for the United States District Court for the District of Maryland United States District Court for the District of Maryland
  7. [7] Guidelines Relating to the Discovery of Electronically Stored Information United States District Court for the Northern District of California
  8. [8] Discussion of Electronic Discovery at Rule 26(f) Conferences United States District Court for the District of Minnesota
  9. [9] Federal Rule of Evidence 901 — Authenticating or Identifying Evidence Legal Information Institute, Cornell Law School
  10. [10] NIST SP 800-86 — Guide to Integrating Forensic Techniques into Incident Response National Institute of Standards and Technology
  11. [11] Electronic Crime Scene Investigation: A Guide for First Responders, 2nd Edition National Institute of Justice, U.S. Department of Justice
  12. [12] NIST SP 800-101 Rev. 1 — Guidelines on Mobile Device Forensics National Institute of Standards and Technology
  13. [13] SWGDE Best Practices for Digital Evidence Collection Scientific Working Group on Digital Evidence
  14. [14] SWGDE Published Documents — Best Practices and Position Papers Scientific Working Group on Digital Evidence

CustodyTrack creates tamper-evident chain-of-custody records that any third party can verify. See how it works →

For this audience: Chain of Custody for Law Enforcement & Crime Labs