Criminal Law Articles

Digital evidence in Turkish criminal proceedings

A legal examination of digital records: lawful acquisition, technical integrity, attribution and the defence’s ability to challenge the evidence.

Published by: KANTARCİ Law OfficePublished:
Digital evidence in Turkish criminal proceedings

1. Why does digital evidence need particular care?

In a criminal case, saying that ‘messages were found on the phone’ can end the discussion far too soon. It should begin a series of questions. Who was using the phone? What decision authorised its seizure? Was access to its contents separately authorised? Did the examination cover the whole device or a particular period or type of data? Is the material in the case file a complete, unaltered representation of the original? Does a message sent from an account establish who actually wrote it at that moment? Could the defence examine the underlying data and the methods used?

Three issues must remain distinct: whether the data was obtained lawfully; whether it is technically reliable and can be attributed to a particular person; and whether it proves the alleged offence. Lawfully obtained material may be incomplete or open to manipulation. A technically sound record may come from an unauthorised search. Even lawful, reliable data may not establish the elements of an offence without the surrounding conversation.

These are not questions for technical specialists alone. A sound legal assessment requires the search and seizure decisions, procedural records, copying process, underlying material examined by the expert and the court’s response to objections to be read together.

2. What counts as digital evidence?

Digital evidence is data created, processed, transmitted or stored electronically that may help establish what happened. It can include a phone’s messages, call history, photographs, videos, location data, application logs and contacts. Computer files, email records, cloud backups, social-media activity, CCTV footage and vehicle or device logs also fall within this broad category.

These records are not all obtained in the same way or equally persuasive. Traffic data lawfully supplied by a service provider is different from a screenshot taken on someone’s own phone. A forensic image may contain much more technical information than a few lines on a screen, but making an image does not resolve every question of attribution or meaning. Identifying the type of evidence is the first step in choosing the applicable legal framework and technical examination.

3. Seizing a phone does not give unrestricted access to its contents

A mobile phone is a physical object, but no longer merely a communication tool. It may hold years of correspondence, photographs, location history, health and financial information, professional contacts and considerable data about other people. Taking the device into custody is therefore legally distinct from searching, copying and analysing its data.

Finding and recording a phone during a search does not automatically authorise an unlimited examination of everything it contains. The basis for physical seizure and the separate basis and scope of digital examination must each be identified. The decision or order should specify the device, its connection to the suspected offence, the purpose of the search and why the measure is necessary. A general suggestion that ‘evidence may be found’ does not settle proportionality, particularly given the volume of personal data.

Article 20 of the Constitution protects private life, safeguards governing search and seizure, and personal data. The boundary of a digital examination is consequently not just the edge of the device. Legal scrutiny also concerns whether unrelated correspondence, family photographs, health records or third-party information may be viewed, separated and retained, and what happens to it when no longer needed.

4. What conditions does Article 134 of the CMK impose?

In the legislation in force on 8 September 2026, Article 134 of the Turkish Code of Criminal Procedure (CMK) permits searches, copying and analysis of computers, computer programs and computer records used by a suspect during a criminal investigation where there are grounds for strong suspicion based on concrete evidence and no other means of obtaining evidence. A judge’s decision is the rule. Where delay would be prejudicial, a public prosecutor may decide, but must submit the decision for judicial approval within twenty-four hours; the judge must decide within a further twenty-four hours. If the time limit expires or approval is refused, the copies and transcribed material must be destroyed immediately.

For the current provision and commencement note: official Turkish text of the CMK.

These conditions must be considered together. Strong suspicion must rest on concrete evidence, not a general impression. The requirement that evidence cannot be obtained otherwise is a safeguard against making a digital search the first and easiest option. Any urgency must explain why judicial authorisation could not be awaited. When a prosecutor has authorised the measure, the approval deadlines and scope of judicial approval require separate scrutiny.

The provision allows seizure where encryption cannot be overcome, concealed information cannot be accessed or the process would take too long; devices must be returned without delay once the necessary analysis and copies are completed. The text in force also requires all system data to be backed up on seizure, with a copy provided to the suspect or their legal representative. These safeguards enable later scrutiny. A note saying ‘an image was taken’ is not enough: the source device, method, tools, date, time and recorded integrity values must be identifiable.

Article 134 refers expressly to computers, computer programs and computer records. Smartphones’ processing and storage functions make its application important in practice. Nevertheless, phone-related data is not always obtained through the same procedure. Forensic extraction from a device held by police, a record supplied by another participant in a conversation, provider data and content obtained from a cloud account each require their own analysis of authority and safeguards.

5. The same message can reach a case file in four different ways

The presence of a WhatsApp conversation says nothing by itself about how it was obtained. It may have been extracted from a suspect’s seized phone, shown by a complainant from their own device, supplied by a third party who received a screenshot, or requested from a cloud backup or service provider. The same words can raise different verification questions depending on their route into the file.

For examination of a suspect’s device, the authorisation, competent authority, scope, deadlines and technical process come first. If a participant supplies their own record, its source and production method, completeness and correspondence with the other participant’s records matter. A third-party image adds links to the transmission chain, requiring examination of the original source and possible intervening changes. Cloud or provider records raise questions about the legal basis of the request, the response’s scope, the account’s connection to a person and details such as time zones.

Whether a message was lawfully obtained cannot be answered before its acquisition history is established. The first task is not to read a screenshot’s contents, but to identify how it entered the file and which record documents that process.

Different sources require different checks

The table does not determine the outcome of a case. It identifies initial checks appropriate to each type of evidence.

On narrow screens, scroll horizontally to see all columns.

Checks for different types of digital evidence
EVIDENCE TYPEROUTE INTO THE FILEINTEGRITY / VERIFICATIONMAIN LEGAL RISKQUESTION TO ASK
Forensic image of a deviceTaken from a seized phone or computer through an authorised examination.Match the device identifier, copying record, method, hash and chain of custody.Exceeding the authorisation; approval of a prosecutor’s decision; failure to separate unrelated data.Does the decision actually cover this device and data? Could the defence access a copy that can be examined?
Application conversation / exportObtained from a device database, account export or cloud backup.Compare source data, export time, the complete conversation and records on the other device.Selective extracts, synchronisation differences, old backups or uncertainty about the account’s actual user.What was the source, and how were dates, times and the user’s identity verified?
Screenshot / photograph of a screenSupplied by a participant in the conversation or a third party.Seek the source device, original file, full conversation, visual consistency and independent corroboration.Cropping, combining images, changed profile names, missing context and an uncertain transmission chain.Who made the image, from which device and when? Can the original record still be examined?
Provider / traffic recordSupplied in the service provider’s official response to a competent authority’s request.Check the request and response, subscriber/session matching, timestamps and time zones.Confusing content with traffic data; attributing activity solely from the subscription.What does the record establish or leave unproven? How is it linked to the actual session user?
Cloud backup / account archiveObtained from the account, a linked device or a provider’s response.Examine account ownership, backup date, synchronisation logs and device links.Overbroad data collection, third-party information, outdated snapshots and limits on the requesting authority’s powers.Which dated account snapshot was examined? Was the scope limited to the investigation’s purpose?

Note: hashes, forensic images and provider responses are useful verification tools. None automatically establishes a message’s author, criminal intent or every element of an offence.

6. What do a forensic copy and a hash establish?

A forensic copy or image reproduces data from a storage medium in a form suitable for examination. Its purpose is to create a reproducible, reviewable working basis while minimising interference with the original device. A hash is a numerical digest calculated from a dataset. Applying the same method to unchanged data produces the same result, helping test whether a copy changed during the process.

These tools should not be asked to prove more than they can. Matching hashes may show that the examined copy was identical at two particular moments. They do not, by themselves, establish who wrote a message, used an account or possessed criminal intent. Conversely, the absence of a recorded hash does not make evidence necessarily fabricated in every case, although it complicates integrity checks and may deepen reliability concerns.

A proper technical record should connect the device’s identifying details, handover and seal condition, personnel involved, dates and times, hardware and software, type of copy, integrity values and outputs produced. The relationship between the original material, examination copy and working copy should be clear. Every transfer of custody needs its own record. Gaps do not necessarily prove alteration, but the prosecution must explain them sufficiently to address that possibility.

7. Why is account ownership not enough to identify a message’s author?

A phone number registered to someone does not conclusively establish that they wrote every message sent using it. The subscriber, device owner, registered account user and actual sender may be the same person, but not always. Shared phones, open web sessions, linked devices, transferred numbers, restored backups and compromised accounts can affect attribution.

Attribution therefore requires mutually supporting evidence, not a single indicator. Relevant material may include possession of the device, session information, contacts, personal details in messages, the other participant’s records, call and connection data, characteristics of photographs or audio, witness statements and external events. A name or profile photograph in a message is not adequate technical verification, particularly where only a screenshot is available.

Meaning also depends on context. A few lines without the preceding or subsequent conversation can alter the interpretation of irony, the seriousness of a threat, the subject of negotiations or the event being discussed. In group conversations, the intended recipient, forwarded content, original quoted messages, deleted passages, edit indicators and reactions may matter as much as the words. Voice messages require attention to the speaker’s identity; photographs and video to recording dates and differences between source and transferred files.

8. Can a screenshot be evidence?

A screenshot can prompt an investigation, gain significance alongside other evidence or show how a conversation appeared at a particular moment. It would be wrong to say that screenshots can never be evidence. The opposite assumption is equally unsound: submitting an image does not require its contents to be accepted as authentic, complete or attributable to a particular person.

Screenshots are often selective extracts. They may lack a filename, creation date, device information or access to the application’s underlying database. They can be cropped, combined or recreated with changed names and profile pictures, or omit passages that alter the meaning. Printing them can make these limitations even less visible.

Practical questions include who took the image, on which device and when; whether the source device still exists; whether the complete conversation or an export is available; and whether the other device holds matching messages. Dates, times, numbers and account details should be consistent. Signs of cropping, overlays or inconsistent fonts require attention. Bank transactions, location data, CCTV, witness accounts or subsequent conduct may provide independent corroboration.

The answers are case-specific. Courts should assess a screenshot through its acquisition, verifiability, the response to objections and its relationship to other evidence, not label it abstractly as ‘conclusive’. A defence objection should likewise identify concrete technical or contextual concerns rather than stop at ‘it could have been edited’.

9. Does recovering a deleted message recover its meaning?

Forensic examination may recover a deleted file or message fragment, but the result is not always complete. Content may be fragmented, dates lost, data overwritten or only a small remnant left in a cache. Deletion itself does not establish consciousness of guilt. Automatic application cleanup, device changes, storage settings and ordinary user behaviour must also be considered.

Cloud backups call for similar care. Device and backup records may concern different dates. Multiple linked devices, synchronisation, time zones and restoration can affect what appears in the data. A report should not merely state that data was ‘found’: it should explain where, its relationship to other structures and the limits on its interpretation.

10. Can unlawfully obtained digital evidence support a judgment?

Article 38(6) of the Constitution expressly prohibits admitting findings obtained unlawfully as evidence. Article 206 of the CMK requires rejection of unlawfully obtained evidence; Article 217 permits an alleged offence to be proved only through lawfully obtained evidence; and Article 230 requires the judgment’s reasons to identify accepted and rejected evidence, including evidence obtained through unlawful methods. Ease of copying digital data does not weaken these rules.

The alleged unlawfulness must nevertheless be identified precisely. Problems with physical seizure, lack of authority to examine contents, exceeding the decision’s scope, missed approval deadlines, gaps in integrity records and denial of defence access are different issues. Each rests on specific facts and documents. Its consequences require assessment at the relevant procedural stage and in light of the evidence’s role in the judgment.

In Helin Yusuf, the Constitutional Court considered evidence whose unlawfulness was apparent or had been established by judicial authorities. It examined whether the material was used at trial, whether it was sole or decisive evidence, whether authenticity and reliability could effectively be challenged, and the effect on the proceedings as a whole. The decisive use of photographs from unlawfully seized digital material, together with the failure to address substantial objections, led to a finding of violation (application no. 2020/14678, 14 January 2025, §§ 53–61).

This individual-application approach is not permission to relax the domestic exclusion of unlawful evidence. Rather than acting as a further appellate court and deciding every admissibility question afresh, the Constitutional Court examines the effect of established unlawfulness on a fair trial. Trial and appellate courts must determine the allegation by reference to the particular legislation, procedure and evidence, and explain their conclusions in the judgment.

11. Could the defence genuinely scrutinise the digital evidence?

Reading an expert report’s conclusion is often insufficient. A report may say ‘a message was identified’, yet omit which copy was examined, the search criteria, how deleted data was recovered, the database field containing the message or whether the findings can be reproduced. Without this information, effective scrutiny is not possible.

In Yankı Bağcıoğlu and Others, the Constitutional Court’s Plenary examined challenges to the authenticity of digital evidence supporting convictions. Requests for access to forensic images and an expert examination were refused; analyses commissioned by the investigating authority carried decisive weight. General references to state secrecy and the lawfulness of the search did not answer the defence’s need to test authenticity. The Court found a violation of the right to a fair trial (application no. 2014/253, 9 January 2015, §§ 67–76).

The decision does not create a mechanical rule requiring an identical form of copy in every case or a new expert after every objection. The data, confidentiality needs and circumstances matter. Any restriction must, however, be accompanied by adequate safeguards to offset the defence’s disadvantage, specific reasons for refusal and an effective opportunity to dispute the technical finding on which a conviction relies.

For defence counsel, the examination file should connect at least the search and examination authorisation, seizure and handover records, seals, copying record, integrity values, examination instructions, specialist or expert report, appendices, the selected data’s location within the complete source, and return or destruction records. Missing documents have different consequences, but it must be clear what each omission prevents the defence from checking.

12. What changed with the Constitutional Court’s 2026 annulment ruling?

In its judgment E.2023/128, K.2026/36 of 12 February 2026, the Constitutional Court examined Article 134’s computer-search, copying and seizure rules against the rights to private life and personal-data protection. It accepted the legitimate aims of combating crime and establishing the facts, and recognised safeguards including strong suspicion, inability to obtain evidence otherwise, judicial authorisation, objections and compensation.

The central concern was retention and deletion after collection. The legislation did not adequately regulate how long personal data would be kept after a final judgment, deletion procedures, restrictions on processing if it was not deleted, the scope and conditions of retention, or the individual’s rights to request deletion or restriction. The Court considered the interference disproportionate (§§ 60–68). It annulled specified parts of the first sentences of paragraphs 1 and 2 as unconstitutional, then annulled the remainder, which could no longer operate, under Article 43(4) of Law no. 6216 (§ 71; operative parts A–C). The outcome therefore covers the whole article, including paragraph 5, not just paragraphs 3 and 4.

The Court did not say that digital searches are unnecessary or inherently unconstitutional. It required legislation to balance investigative needs with the individual’s data rights throughout retention, access, restriction and deletion, not just collection. The decision takes the legal analysis beyond asking whether a search warrant exists.

The annulment provisions were published in Official Gazette no. 33264 on 25 May 2026, with commencement deferred for nine months. Article 134 therefore remained in force on 8 September 2026; the annulment takes effect on 25 February 2027. The footnote to Article 134 in the Legislation Information System also identifies this date. Assessments after that date must check intervening amendments and transitional provisions. The ruling must not be presented as automatically making every earlier digital search unlawful.

Judgment and commencement: AYM E.2023/128, K.2026/36 · Article 134 of the CMK and its footnote.

13. How should a digital-evidence file be examined?

The useful approach is to trace evidence from acquisition to its use in the judgment, rather than work backwards from an expert report’s conclusion through assumptions.

First, identify the material: a full-device forensic image, a conversation extracted from an application database, a screenshot, a provider response or merely a police record of observations. Then establish from whom and where it came, the connection to the suspicion, and the legal basis for the operation.

Next, examine the authorisation’s scope: offence, person, device, period and type of data. Are any grounds of urgency specific? Was a prosecutor’s decision submitted for judicial approval in time? Did the examination exceed the powers granted?

Third, trace technical integrity from handover and copying to the examination copy and report appendices. Can the device and its copies be distinguished? Were methods, tools and software versions recorded? Do hashes, seals and custody records match? Could another specialist reproduce the result?

Fourth, test attribution and context: the connection between account and person, possible use by someone else, completeness of conversations, time-zone and synchronisation differences, and independent corroboration. Finally, assess effective defence access to the material and methods, responses to objections and the evidence’s actual weight in the judgment.

This sequence avoids getting lost in technical detail and makes objections specific. Instead of asserting that ‘digital evidence is unreliable’, it identifies which operation compromised which safeguard and how that affects the accuracy of the evidence or the judgment.

14. Frequently asked questions

Can police examine a seized phone without separate authorisation?

Finding and physically retaining a phone is distinct from searching its data. An answer requires the legal basis, competent authority, urgency, scope and circumstances to be examined. Whole-device examinations particularly require Article 134 and fundamental-rights safeguards to be assessed together.

Can a WhatsApp screenshot be evidence in a criminal case?

It can be assessed, but is not automatically conclusive or unalterable. Relevant checks concern the source device, full conversation, account-to-person connection, technical consistency, production method and corroboration. Its evidential weight depends on these factors together.

Does a message’s phone number prove who sent it?

Number ownership is relevant but does not always identify the actual user. Possession of the device, linked sessions, conversation contents, records on the other device and consistency with external events may provide supporting evidence. A profile name or photograph alone does not establish attribution.

Is recovering deleted messages enough for a conviction?

Merely finding a deleted message does not provide an adequate legal assessment without its integrity, source, dates and context. Deletion does not automatically establish criminal intent. The technical finding must be considered with the other evidence and the elements of the alleged offence.

Can digital evidence alone support a conviction?

There is no automatic answer based solely on the evidence being digital. Lawful acquisition, authenticity, reliability, connection to the accused, effective challenge by the defence and proof of all elements beyond doubt must be assessed. Sole or decisive evidence makes procedural safeguards and the court’s reasons especially important.

15. Conclusion: a digital record needs a traceable process

Digital evidence derives its strength not from the striking words on a screen but from an explainable route into the file. Lawful authority, proportionate scope, documented technical work, preserved integrity, reliable attribution, complete context and effective defence objections are links in the same chain.

Seizing a phone does not turn everything it contains into unquestionable evidence. A screenshot’s vulnerability to alteration does not make it worthless from the outset. Acquisition, technical reliability and probative force should be examined separately, without treating digital records as infallible or rejecting them wholesale.

The 2026 annulment ruling adds another dimension. Personal-data safeguards do not begin and end with searching and copying: retention periods, access, purposes of use, restrictions and deletion also need a clear statutory framework. During the transition, the commencement position and any subsequent legislative amendments must be checked.

A case-specific conclusion comes from examining decisions, procedural records, forensic copies, report appendices and objections together, not from a general article online. Effective defence often depends less on one sweeping allegation than on explaining precisely which link in the chain cannot be checked and why.

References and date note

1. Constitution of the Republic of Türkiye, particularly Articles 13, 20, 36 and 38.

2. Code of Criminal Procedure, Law no. 5271, particularly Articles 134, 206, 217 and 230. Current official Turkish text.

3. Law no. 7145, Article 16: the 2018 amendment to Article 134 of the CMK.

4. Constitutional Court, E.2023/128, K.2026/36, 12 February 2026; Official Gazette, 25 May 2026, no. 33264. Official judgment.

5. Constitutional Court, Helin Yusuf [Second Section], application no. 2020/14678, 14 January 2025.

6. Constitutional Court, Yankı Bağcıoğlu and Others [Plenary], application no. 2014/253, 9 January 2015.

7. Constitutional Court, Orhan Kılıç [Plenary], application no. 2014/4704, 1 February 2018.

8. The Code of Criminal Procedure on this website. CMK page — Turkish text.

The current official CMK text and the full judgments in AYM E.2023/128, K.2026/36, Helin Yusuf and Yankı Bağcıoğlu and Others were checked for the Turkish source article on 8 September 2026.

This article provides general legal information. Decisions, procedural records, technical material and current legislation must be examined together in an individual case.

Related reading

All criminal-law articles