In short
- ✓Capture first, report second: by the time the police act, posts, profiles and scam shops are often gone.
- ✓Hand over a package, not a screenshot: Evidence ZIP on a data carrier or secure link, the printed PDF report and the SHA-256 hash stated in the complaint.
- ✓Describe the chain of custody in a few sentences: who captured what, when, with which tool and where the files have been since.
- ✓Keep originals untouched: phone, messages, accounts and emails stay as they are, ready for the police to examine.
- ✓Ask the police to request a preservation order from the platform in parallel – since 18 August 2026 the EU e-Evidence Regulation makes this faster across borders.
Why the police often cannot secure web content in time
Most people assume that once they file a criminal complaint, the police will take care of the evidence. For anything on the internet, that is risky. Between the moment a crime is reported and the moment an officer actually opens the link, days or weeks can pass – and web content is the most volatile evidence there is.
This is not a criticism of investigators. It is a structural problem that every police force in Europe faces:
- Volume: cyber units receive far more reports of online fraud, harassment and threats than they can process on the day they arrive.
- Deletion: perpetrators delete posts, rename profiles and take scam shops offline as soon as they suspect a report. Platforms also remove content after a user report – together with the visible evidence.
- Cross-border data: the platform and its servers are usually in another country. Obtaining data through classic mutual legal assistance (MLAT) has traditionally taken months.
- Access: the police need a legal basis and often a court or prosecutor decision before they can request data from a service provider.
Capture first, report second
The single most useful thing a victim, lawyer or company can do is to secure the content before reporting it to the platform or confronting the other side. Reporting, blocking or commenting often makes the content disappear. A sensible order of steps:
- Collect every relevant URL: the post, the profile, the shop, the ad, the payment page, the comment thread.
- Capture each public URL forensically – full page, source HTML, network log, SHA-256 hashes and a qualified timestamp.
- Capture content behind a login (private messages, orders, closed groups) from your own logged-in browser session.
- Save originals that arrived by email or messenger in their original format and do not edit them.
- Only then file the criminal complaint and, if you want, report the content to the platform.
A screenshot alone is an editable image with no reliable time, no source code and no proof that it was not altered. GetProofAnchor captures a public URL server-side and produces an Evidence ZIP with a full-page screenshot, the HTML/DOM, a HAR network log, metadata, a SHA-256 manifest and hash chain, an eIDAS qualified timestamp from an EU-accredited trust service provider, a Bitcoin OpenTimestamps anchor and a PDF report. For content behind a login, the browser widget on subscription plans captures what you see in your own session.
What a usable handover to the police looks like
Police and public prosecutors work with a written file. Whatever you hand over has to fit into that file, be readable by an officer who is not an IT specialist and still be verifiable by a digital forensics unit later. A usable handover has five parts:
- The Evidence ZIP files on a USB stick or other data carrier, or via a secure download link if the authority accepts that. Hand over copies – keep your own copy of every file.
- The PDF report of each capture, printed, so it can go straight into the paper or electronic file.
- The SHA-256 hash of each Evidence ZIP, written out in the complaint itself. That hash ties the text of the complaint to exactly these files.
- A short description of who captured what, when and how (see the next section).
- A list of the URLs with one line each explaining why it matters: the fraudulent ad, the threatening post, the fake profile.
Why the hash belongs in the complaint
A SHA-256 hash is a fingerprint of a file. If a single byte changes, the hash changes completely. By stating the hash in your signed complaint, you fix the content of the evidence at the moment you file it. Anyone – the officer, the prosecutor, the defence, the court – can later recalculate the hash and see whether the files are the same ones you handed over.
What exactly is inside an Evidence ZIP and how to read it →
Chain of custody: who, what, when, how
Chain of custody means that at every moment someone can explain where the evidence came from and who has had it since. ISO/IEC 27037, the international guideline for identifying, collecting, acquiring and preserving digital evidence, emphasises that acquisition should be documented, repeatable and justifiable. For a victim or a lawyer, that translates into a short, factual paragraph in the complaint:
- Who: the name of the person who made the capture, or the service that made it on their behalf.
- What: the URLs captured and, for login-protected content, the account from which it was viewed (your own).
- When: date and time of each capture, as shown by the qualified timestamp in the report.
- How: the method and tool used – server-side forensic capture, or capture in your own browser session.
- Since then: where the files have been stored and that they have not been modified, which the hash confirms.
Keep it sober. You are not arguing the case in this paragraph; you are making it easy for the police to trust and re-check your material.
How ISO/IEC 27037 applies to web evidence acquisition →
What to write in the criminal complaint
There is no special legal form for attaching web evidence, but a clear structure saves the police time and makes it less likely that your evidence is overlooked. A proven structure:
- Your identity and contact details, and whether you act as the victim, as a lawyer on behalf of a client or for a company.
- What happened, in chronological order, with dates, amounts and platforms.
- Who you suspect, if known – usernames, profile URLs, phone numbers, IBANs, email addresses.
- A list of evidence: each Evidence ZIP with its file name, capture time and SHA-256 hash.
- The chain-of-custody paragraph: who captured what, when and how.
- Originals you keep available for examination: phone, messages, emails, bank statements.
- A request that the police ask the platform or service provider to preserve and hand over the data.
Do not alter the originals – and keep the device
A forensic capture of a web page does not replace the originals on your own devices. The police may want to examine them, and the defence may ask whether anything was changed. Therefore:
- Do not delete chats, messages or emails with the suspect, even if they are upsetting. Archive them if you must, but do not remove them.
- Do not reset, sell or replace the phone or computer on which you received the messages until the case is over, or at least until the police confirm they do not need it.
- Do not edit, crop or annotate the evidence files. If you want to highlight something, make a separate marked-up copy and say that it is a copy.
- Do not forward originals in a way that strips metadata, such as re-saving emails as screenshots. Export them in their original format where possible.
- Do not reply to the perpetrator in a way that could provoke deletion before you have captured everything.
Ask for a preservation order from the platform in parallel
Your capture secures what was publicly visible or visible in your own account. It cannot show what only the platform knows: IP addresses, login times, registration data, deleted messages, payment details. Only the authorities can obtain that, and only while the provider still keeps it.
Since 18 August 2026, Regulation (EU) 2023/1543 on European Production and Preservation Orders – the e-Evidence Regulation – applies. It allows a judicial authority in one member state to order a service provider offering services in the EU to preserve or produce electronic evidence directly, instead of going through slow mutual legal assistance. Victims cannot issue these orders themselves, but you can ask for them:
- Write in the complaint that you ask the police or prosecutor to request preservation of the suspect's account data from the named platform without delay.
- Name the exact platform, profile URL, username or ad ID, so the order can be targeted.
- Mention that the content may be deleted soon and that your own capture documents what was visible at a precise time.
How police and prosecutors can verify the evidence independently
A good evidence package does not require the authority to trust the victim or the tool. It should be checkable by anyone, without an account and without contacting the vendor. For a GetProofAnchor Evidence ZIP, verification works like this:
- Recalculate the SHA-256 hash of the ZIP and compare it with the hash stated in the complaint.
- Upload the ZIP at /verify, or run the open-source gpa-verify command-line tool fully offline on a forensic workstation.
- Check that every file matches the manifest and hash chain and that the qualified timestamp is valid.
- Check the Bitcoin OpenTimestamps anchor as a second, independent proof of existence at that time.
Under Article 41(2) of the eIDAS Regulation, a qualified electronic timestamp enjoys a presumption of the accuracy of the date and time it indicates and of the integrity of the data to which that date and time are bound. That does not decide the case – courts assess evidence freely – but it makes forensic captures much harder to challenge than screenshots.
The complete guide to eIDAS qualified timestamps →
Country notes: where to file the complaint
Across the EU you can file a criminal complaint with the police or directly with the public prosecutor. The procedure for handing over digital evidence differs slightly per country:
- Czech Republic: a trestní oznámení can be filed with any Policie ČR office or with the státní zastupitelství, in person, in writing or electronically. Bring the data carrier and printed reports if you file in person.
- Germany: a Strafanzeige can be filed at any police station, with the public prosecutor, or via the online police station (Onlinewache) of your federal state. Online forms usually cannot take large files, so mention the Evidence ZIPs and hashes and offer to provide them.
- France: a plainte can be filed at a police station or gendarmerie or sent to the procureur de la République. For certain online scams, private individuals can file online via the THESEE platform; a pré-plainte en ligne is also available for some offences.
Scammed online? The first steps to take and the evidence to secure →
For investigators, corporate security and authorities
Lawyers, corporate security teams and private investigators preparing a complaint for a client should treat web evidence like any other exhibit: capture early, document the method, give each capture a clear reference and deliver hashes with the file. Doing this well also protects you when the defence questions how the material was obtained.
Police and authority staff who capture web content themselves every day need a different tool than an occasional victim. The GetProofAnchor Forensic Browser is a Windows desktop application for professionals – investigators, police, authorities and law firms – that captures web content during an investigation with the same sealed, independently verifiable output. It is available from 290 € per year.
Forensic Browser for investigators and authorities →
Web evidence workflows for investigators and corporate security →
For investigators and authorities
Web evidence with a chain of custody that holds
Capture public and behind-login content in a documented workflow aligned with ISO/IEC 27037 — or run captures on your own workstation with the Forensic Browser for Windows.
Related guides
-
ISO/IEC 27037 and web evidence acquisitionThe international guideline behind chain of custody for digital evidence.
-
eIDAS qualified timestamps: complete guide 2026Why a qualified timestamp carries a legal presumption in the EU.
-
Scammed online: what to do and what evidence to keepFirst steps for victims before going to the police.
-
What courts actually look for in online evidenceHow judges assess screenshots, captures and witness statements.
Frequently asked questions
How do I submit online evidence to the police?
Capture the content forensically first, then file the criminal complaint and hand over the Evidence ZIP files on a USB stick or data carrier, the printed PDF reports and a list of SHA-256 hashes. Add a short description of who captured what, when and how.
Are screenshots enough for a criminal complaint?
Screenshots can start an investigation, but they are easy to edit and prove neither the time nor the source. A forensic capture with source code, network log, hashes and a qualified timestamp is much harder to challenge.
Will the police secure the web page themselves?
Sometimes, but often too late. Because of case volume and cross-border procedures, content is frequently deleted before an officer opens the link. Secure it yourself before reporting it.
Can I ask the police to get data from the platform?
Yes. Ask in the complaint that the police or prosecutor request preservation and production of the account data. Since 18 August 2026, the EU e-Evidence Regulation allows judicial authorities to address such orders directly to service providers offering services in the EU.
How can the police check that my files were not altered?
By recalculating the SHA-256 hash and comparing it with the one in your complaint, and by verifying the package at /verify or offline with the open-source gpa-verify tool, including the qualified timestamp.
Should I delete the messages after I have captured them?
No. Keep the original messages, emails and the device until the case is closed or the police confirm they do not need them. The capture complements the originals; it does not replace them.
This article is general information, not legal advice. Criminal procedure differs between countries; for a specific case, consult a lawyer or the competent police or prosecutor's office.