Your AI Chat History May Be Evidence: Why Legal Holds Need to Change

Employees are increasingly using AI assistants to test ideas, summarise information, draft communications and think through commercial decisions. These exchanges may feel informal, more like private conversations than business records. In litigation or an investigation, however, prompts and responses can provide direct evidence of what a person knew, what options they considered and why a …

New Privacy Rules Are Coming: What IPP3A Means for Digital Investigations

From 1 May 2026, New Zealand organisations will face a new privacy obligation when they collect personal information about someone from another source. Known as Information Privacy Principle 3A, or IPP3A, the new rule will generally require an organisation to tell a person when information about them has been collected indirectly. That sounds straightforward. In …

The Screenshot Problem: Why Digital Evidence Needs More Than a Convincing Image

Screenshots have become a routine part of litigation and investigations. They are used to record text messages, social media posts, online transactions, workplace communications, website content and activity within mobile applications. They are easy to capture, easy to share and immediately understandable to a reviewer. They are also increasingly easy to fabricate. On 24 February …

Microsoft Purview eDiscovery Is Changing Again: What Legal Teams Need to Do Before 16 February 2026

Microsoft has announced two changes to Purview eDiscovery that will affect how legal, investigation and compliance teams search, review and export Microsoft 365 evidence. From 16 February 2026, the Content Search area of Microsoft Purview eDiscovery will become a more limited search-and-export tool. It will no longer support review sets or case-level data sources. Microsoft …

Microsoft Teams Private Channel Evidence Is Moving: What Legal Teams Need to Check for 2026

Microsoft Teams has become an important source of evidence in workplace investigations, litigation, regulatory inquiries and internal disputes. Messages sent through Teams may record decisions, instructions, approvals, complaints and informal discussions that do not appear in email. Private channels are particularly significant because they are often used for sensitive projects, management discussions, investigations and restricted …

Deepfakes Enter the Evidence Room: What New Zealand Legal Teams Need to Preserve Now

Deepfakes are no longer only a concern for celebrities, elections and online misinformation. They are becoming a practical issue for lawyers, investigators and organisations relying on photographs, voice recordings, CCTV footage, video calls and social media content as evidence. The issue became particularly timely in New Zealand following the introduction to Parliament in late October …

How digital forensics is used to solve theft of intellectual property cases

Digital forensics is a specialised field that involves the collection, analysis, and preservation of digital evidence to investigate and solve various types of crimes, including theft of intellectual property cases. Intellectual property (IP) refers to intangible assets, such as trade secrets, copyrights, patents, and trademarks, that are valuable to individuals and organisations. Digital forensics can …

Timezone

The analysis of artifacts and their timestamps are extremely useful in piecing together what occurred on a computer system. Almost every forensic artifact has date and time information, such as the last modified date of a document, the date of a user login, or the duration that a certain connection was in place. These times …

Thumbnails

As is often the case, Windows features can end up being useful evidence to forensic examiners. For example, the Windows operating system makes the experience of viewing files in Windows explorer smoother by using ‘thumbnails’ of images. When examining images, we often rely on “thumbs.db” files and the “thumbcache”, both of which serve generally the …

Deleted Files

Just like a fingerprint, a file can leave behind evidential traces, well after it has been deleted. Here we explore what kinds of information can be recovered after a file has been deleted. Take for example a business owner suspicious of their ex-employee. The owner believed their ex-employee took sensitive information and copied it into …