Co-authored by Jerry Bui, Senior Vice President of Digital Forensics, and Steve Davis, Vice President of Forensics and Investigations
Mobile device collection has become one of the most failure-prone steps in digital forensics and eDiscovery because people still expect it to work like a traditional computer forensic image. A laptop image feels linear: files, folders, and a bit-by-bit copy that the examiner controls. Phones are different. The operating system and device security model mediate access; the most important evidence often lives inside app databases; and “forensic” can mean a best-practice logical workflow rather than a true physical bitstream. That mismatch in expectations is where projects start to go sideways, especially when counsel assumes a quick pull will capture everything from iMessage to third-party chats.
A defensible mobile device collection starts with communication, scope, and clear stakeholder alignment. Before anyone touches a custodian’s iPhone or Android device, you need a kickoff that defines goals, data sources, and constraints: which messaging apps matter, what date range is required, whether the matter is communication-centric, and what will happen if the device is locked down or encrypted. This is also where chain of custody, documentation, questionnaires, and “white glove” custodian handling reduce friction. In BYOD environments, commingled personal and work data raises privacy and proportionality concerns, so setting expectations early prevents the Pandora’s box moment when the collection reveals how much sensitive information is even in scope.
From a workflow perspective, mobile forensics still lives in a collect-to-preserve world. There is rarely a true preservation in place switch for phones, even with MDM, so teams must choose among preservation options and understand trade-offs. A targeted approach may be appropriate for routine ESI collection, but full file system extraction can become necessary when you need deeper forensic analysis, behavioral artifacts, or the possibility of recovering deleted items. That decision affects disruption too: modern devices can hold enormous storage, and a comprehensive collection can take hours to days, which custodians resist because a phone feels like an extension of daily life. The right approach balances defensibility, privacy, speed, and the specific investigative questions.
When data is missing, the analysis does not stop at “it’s not there.” Deleted data, transient databases, rolling storage, and user behavior can create gaps that matter for spoliation assessments and adverse inference arguments. Experienced forensic teams look for the constellation of artifacts that explain absence: location history gaps, browsing history gaps, app usage patterns, timestamps, and metadata changes that might have benign explanations like leave time or device migrations. This is why a village matters. Mobile device forensics demands specialization across iOS, Android, messaging apps, cloud acquisition, and expert testimony. Add the final mile: data normalization and presentation. Converting raw mobile artifacts into reviewable, accurate productions across eDiscovery platforms requires careful parsing, emoji fidelity, and repeatable processes that stand up under cross examination.
Mobile device evidence is often the most important and the most misunderstood source of ESI.
If you’re planning a collection, responding to a discovery request, or evaluating potential spoliation issues, our digital forensics team can help you design a defensible mobile collection strategy that stands up to scrutiny.
Want to go deeper? Listen to the latest episode of Evidence Matters with Bui & Davis, where Jerry Bui and Steve Davis discuss mobile device collection challenges, defensibility considerations, and real-world lessons from the field.