Investigation · Service

Turn digital traces into court-admissible evidence.

Emails, messages, system logs and deleted files are the true witnesses of most disputes. We manage e-discovery processes for the lawful collection and preservation of digital evidence and for locating the relevant record within vast volumes of data.

Overview

Evidence no longer lives in files, but in systems

The critical evidence in commercial disputes and internal investigations today lives in emails, messaging apps, ERP records and cloud systems. This evidence is lost in two ways: by not being preserved in time — or by being collected unlawfully and thereby becoming worthless in court.

Our digital evidence work combines two pillars: on the legal side, evidence determination, preservation letters, KVKK limits and the chain of custody; on the technical side, forensic imaging, data recovery, and locating key records within large data sets together with digital forensics experts. With our Legal Tech team, we configure e-discovery tools to fit your case.

Data & evidence
01

When Does This Apply?

Typical use cases for our digital evidence service.

Disputes & Litigation

Establishing correspondence and records as evidence in contract and shareholder disputes.

Internal Investigation Support

Lawful analysis of system and email data in misconduct investigations.

Deleted Data & Preservation

Recovery of deleted records and urgent determination of evidence at risk of loss.

02

How Does the Process Work?

The three-stage flow we follow in digital evidence matters.

01 · Preservation

We identify evidence sources and prevent loss through retention instructions, forensic imaging, and evidence determination.

02 · Review

We narrow the large data set with e-discovery tools and evaluate the relevant records with a legal eye.

03 · Establishing Evidence

We document the findings with a chain of custody and a technical report, tying them to the litigation or investigation file.

Why Köksal?

A structure that brings law and technology together in one team

Failure in digital evidence often stems from two teams — lawyers and technicians — not understanding each other. With our Legal Tech experience, we do this translation in-house: the technical work is designed from the outset around the legal objective and the evidentiary standard.

  • Law-technology coordination through a Legal Engineering approach
  • KVKK/GDPR-compliant review protocols
  • Defensible findings through chain-of-custody and formal record-keeping discipline
  • Established cooperation with independent digital forensics experts
  • Seamless integration with internal investigation and litigation teams
03

Other Investigation Services

When needed, the same team can seamlessly extend its work to our other solutions in this area.

All Investigation services
04

Related Areas & Legislation

The focus areas, practice areas, desks and legislation connected with this service.

06

The Team Delivering This Service

With our multilingual team of lawyers, well-versed in Turkish and German law, we are by your side.

07

Related Publications

Fresh perspectives and guides from the Knowledge Centre.

Yes, provided they were obtained lawfully. WhatsApp exchanges you were a party to, screenshots and exported records can all be put before a court, and their integrity can be reinforced by having them formally determined before a notary or examined by an expert.What decides it is how the evidence was obtained. The Code of Civil Procedure (No. 6100) provides that evidence obtained unlawfully cannot form the basis of a…

Often, yes. Deleted e-mails and files can frequently be recovered through server backups, mailbox retention windows, shadow copies and forensic imaging of drives, but the window narrows quickly, because systems overwrite freed space over time. That is why preservation should begin the moment a suspicion arises: a legal hold stops routine deletion and log rotation, and forensic imaging captures the data with a verifi…

Because the value of a digital record depends as much on how it was obtained and kept as on what it says. If you cannot document who took the data, when, and by what method, the other side will argue that the record may have been altered afterwards or obtained unlawfully — and the evidence becomes something to litigate about rather than something to rely on.The chain of custody is the unbroken record that closes tha…

Not by reading them one by one, but through e-discovery. The relevant data sources — mailboxes, shared drives, backups — are first collected and copied securely; the data set is then narrowed in stages by date range, by party or person, and by key concept. Duplicates and irrelevant records are removed, the smaller remaining set is reviewed by a lawyer with a legal eye, and the relevant items are separated into the e…

In a badly designed review, yes — the risk is real. Examining an employee’s email, device or system logs means processing personal data, so the review is bound by the core principles of the Personal Data Protection Law (No. 6698): a specific and legitimate purpose, a scope limited and proportionate to that purpose, and prior notice to the employee. An unlimited, covert, just-in-case sweep exposes you to a KVKK sanct…

Service

Get the right legal support for Digital Evidence & E-Discovery.

Let us define the solution best suited to your needs, together with our experience in Türkiye and the DACH region.