The Google ecosystem today comprises hundreds of services — from the search engine, through Gmail, YouTube, Google Drive, Google Maps, Google Ads, Blogger, Android, to analytical and location tools. Many of these services contain information about a user's activity which – once properly secured – can constitute valuable evidentiary material in pre-trial or court proceedings.
Cooperation with Google in this respect takes place on strictly defined terms, in compliance with international law, privacy protection and the standards of evidentiary proceedings.
1. Entities and the scope of data in the Google ecosystem
The data collected by Google is processed by:
Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA)
and, for EU users:
Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland)
Google may disclose data in three basic categories:
2. Google's official portal for law enforcement
Google runs a dedicated service: https://lers.google.com/signup_v2/landing (Law Enforcement Request System – LERS)
This is the official channel for submitting:
- Preservation Requests,
- Legal Process Request (Subpoena / Court Order),
- Emergency Disclosure Requests (life-threatening situations).
Every request must be submitted by a verified law-enforcement body, using an official e-mail address (e.g. @gov.pl, @prokuratura.gov.pl, @policja.gov.pl).
3. NON-CONTENT DATA – technical and login data
Within non-content data requests, Google may provide, among other things:
- the account identifier (Google Account ID, e-mail),
- the date the account was created,
- access logs (IP addresses, dates, locations, devices),
- data on the operating system and browser,
- Android device identification numbers,
- information about authentication methods (2FA, SMS, e-mail).
This data does not contain the content of communications, but constitutes important metadata that makes it possible to establish the user, location and time of activity.
A request for such information may be based on:
- Article 20c of the Police Act (telecommunications data),
- Articles 218 and 218a of the Code of Criminal Procedure,
- Article 10 of the Act on the ABW and the AW (the Internal Security Agency and the Foreign Intelligence Agency),
- other statutes granting powers to obtain telecommunications data.
4. CONTENT DATA – the content of communications and user materials
The content of Gmail messages, Google Drive documents, YouTube recordings or search history is covered by the secrecy of communications. Google discloses this data only after receiving:
- a court order (Court Order / Search Warrant),
- or an MLAT (Mutual Legal Assistance Treaty) request – in the case of international cooperation,
- in the EU – also via a European Investigation Order (EIO).
In Poland, such requests are transmitted through:
The National Public Prosecutor's Office – Department of International Cooperation
ul. Postępu 3, 02-676 Warsaw
After approval by the US side, the data is transferred in encrypted form (ZIP, P7M), containing CSV, JSON or XML files.
5. PRESERVATION REQUEST – securing data against deletion
Before a body obtains a court order, it can submit to Google a so-called Preservation Request, i.e. a demand for the temporary retention of a user's data for a period of 90 days.
This action prevents its automatic deletion (e.g. after the account is deactivated or Gmail is deleted).
The request should specify:
- the e-mail address / Google Account ID,
- the scope of data (e.g. logs, Gmail, Drive, YouTube),
- the period covered by the preservation,
- the legal basis and the officer's contact details.
The request is submitted via the LERS portal, and confirmation of receipt arrives automatically at the applicant's e-mail address.
Publicly available data – the expert's role
A court digital-forensics expert may independently obtain publicly available data from Google services, such as:
- YouTube (comments, video metadata, publication dates, descriptions, author accounts),
- Blogger (posts, comments, URLs),
- Google Maps (opinions, reviews, user locations),
- Google Search (content snippets, site previews).
This data can be secured using forensic-OSINT tools, APIs or direct-archiving methods, preserving:
- checksums (hash),
- a record of the download time (timestamp),
- the source metadata (URL, ID, publication date).
Material obtained in this way has full evidentiary value with respect to publicly available content.
7. Practical tips for law enforcement
- Secure the data as early as possible – submit a Preservation Request immediately after the account is identified.
- Keep the data separate – a separate request for non-content (technical) and content data.
- Use English – Google requires requests in this language.
- Use an official e-mail address – only requests from official domains are accepted.
- Specify the scope of the request precisely – requests that are too broad are often rejected.
8. Response time and the form of the reply
All data is provided in encrypted form with a certified signature and a case reference number.
9. Cooperation with an expert – analysis of Google data
After receiving the data, the body may commission its analysis by a digital-forensics expert. The analysis includes, among other things:
- verifying the logs (IP addresses, dates, locations),
- analysing JSON/CSV files,
- mapping locations and devices,
- correlating the data with other sources (e.g. Facebook, X, telecoms operators).
In cases of internet crime (fraud, stalking, threats, disinformation, data leaks), the analysis of Google data is often a key stage in reconstructing the perpetrator's actions.
10. Summary
The Google ecosystem is one of the richest sources of data in criminal proceedings. Thanks to cooperation with the Google Law Enforcement Response System (LERS), law-enforcement bodies can:
- secure data (Preservation Request),
- obtain account metadata (Non-content Data),
- request the content of communications (Content Data).
Combined with an expert's analysis, this data makes it possible to establish precisely the time, place, manner and participants of an event – in accordance with the principles of digital forensics and evidentiary requirements.
I invite law-enforcement bodies, prosecutors and law firms to work with me on obtaining, analysing and securing data from the Google ecosystem – including Gmail, YouTube, Drive, Maps and Android. The expert practice has specialist tools for processing large data sets (Big Data Forensic Tools), which enable rapid filtering, log correlation and reporting compliant with procedural standards. We carry out all activities while preserving the integrity of the evidentiary material and in full cooperation with the relevant authorities.