The X (formerly Twitter) platform is one of the most important sources of information online — both in a socio-political and in a criminal context.
In pre-trial and court proceedings, content published on this service increasingly constitutes significant evidentiary material.
From the point of view of law enforcement and digital-forensics experts, there are two basic paths for obtaining data from the X platform:
- non-content data – technical data, so-called metadata (e.g. IP, logins, registration),
- content data – the content of communications (public posts or private DMs).
Below I explain both paths step by step – from a practitioner's perspective.
A. NON-CONTENT DATA – technical and registration data
What does the non-content data category cover?
This is non-public data that describes account activity but does not contain the content of communications. It includes, among other things:
- the account identifier (User ID, @username),
- the e-mail address or phone number linked to the account,
- the date the account was created,
- login IP addresses and timestamps,
- information about the devices, browsers and systems used,
- the account status (e.g. active, suspended, deleted).
In what situations is metadata requested?
A request for metadata is justified when:
- there is a need to establish who used a given account,
- it is necessary to confirm or rule out a link between the account and a natural person,
- it is necessary to examine logs and IP addresses in order to establish the place of login or a correlation between different accounts.
Such data is crucial in proceedings concerning:
- insult, threats, hate speech,
- impersonating others,
- online fraud or extortion.
What does the procedure for obtaining metadata look like?
X provides law enforcement with a dedicated portal: https://legalrequests.x.com
Step-by-step procedure:
- Log in or create an official account on the institution's domain (e.g. gov.pl, gov.eu).
- Select the type of request: Law Enforcement Request → Non-content Data Request.
- Attach a scan or PDF file with the official request (on official letterhead, signed by an authorised person).
- In the body of the request, specify:
- the name of the body and contact details,
- the legal basis (e.g. Article 218 § 1 of the Code of Criminal Procedure, Article 20c of the Police Act, Article 10 of the Act on the ABW and the AW, etc.),
- data identifying the account (URL, @username),
- the period the data concerns,
- the type of information requested (e.g. logs, IP addresses, registration data).
- In practice, X requires the request to be submitted in English and to contain the note: "This request concerns non-content data only."
Where does the request go?
For users from the European Union, the data is processed by:
X Internet Unlimited Company
One Cumberland Place, Fenian Street, Dublin 2, Ireland
Data preservation (Preservation Request)
A law-enforcement body can request X to temporarily preserve data for a period of 90 days (Preservation Request).
This action makes it possible to prevent its deletion until the appropriate procedural decision is obtained.
The form and content of the reply
In response, the body receives data in CSV or JSON formats, which may include:
- a list of logins (IP addresses, dates, operating systems),
- the contact details assigned to the account,
- the account's change history,
- sometimes also information about devices and browsers.
This type of data allows an analyst or expert to reconstruct the pattern of activity and link the account to a specific user or device.
B. CONTENT DATA – the content of communications
Two types of content
In the case of X, two ranges of content data must be distinguished:
- Public content – visible to all users (posts, tweets, comments, reactions, multimedia).
- Non-public content – private messages (Direct Messages), data from protected or deleted accounts.
Public content – available without a request
Public content can be lawfully obtained directly from the X platform, because it is public.
A law-enforcement body or an expert can:
- download it manually,
- secure it using specialist tools (e.g. OSINT-class or forensic tools),
- archive it in a way that ensures integrity (screenshots, HTML reports, CSV export, hash checksums).
Such actions do not require X's consent, because they concern public content.
In practice, they make it possible to document, for example, comments containing insults, threats, incitement to hatred or other statements relevant to the case.
Non-public content – private messages (DM)
Private content is covered by the secrecy of communications and may be disclosed only on the basis of a court decision or an appropriate international request.
Law-enforcement bodies in Poland can obtain such data through:
- a European Investigation Order (EIO) – in relations within the EU,
- an MLAT (Mutual Legal Assistance Treaty) request – in relations with the USA, where X Corp. is based.
Such requests are usually directed to:
The National Public Prosecutor's Office – Department of International Cooperation, Warsaw
Following positive verification, X provides the data in encrypted form, most often as a ZIP or P7M archive.
Typical files provided by X as part of content data:
- messages.json – the content of messages with dates, senders and recipients,
- user_profile.json – account data and its parameters,
- media.csv – metadata of attachments (photos, recordings),
- connections.csv – information about relationships between users.
A comparison of the two paths
D. Good practices for securing data
Regardless of the mode of obtaining data, one should document the method of downloading and the source (URL, date, time, tool), preserve the material in a non-editable form (PDF, CSV, JSON), confirm the integrity of the data using checksums (SHA256 or MD5 hash), and describe the time, context and scope of the download in an official note or an expert opinion.
Evidentiary material prepared in this way has procedural value and can be safely used in proceedings.
E. Summary
Cooperation with the X platform in criminal cases proceeds along two tracks. Technical and registration data (non-content) – obtained by law enforcement through a formal request via the legalrequests.x.com portal. The content of communications (content) – publicly available content can be secured independently by the body or the expert, whereas private data requires the court or international route (EIO / MLAT).
In practice, most analyses carried out by experts in Poland are based on publicly available content, which can be downloaded and preserved safely, in accordance with the principles of digital forensics.
As part of my work as a court digital-forensics expert, I offer support to law enforcement and the judiciary in obtaining, analysing and securing data from social-media platforms, including X (formerly Twitter), in accordance with procedural requirements and the principles of digital forensics.
We also have a dedicated tool for reviewing and analysing large data sets, which significantly streamlines the process of classifying and assessing content in terms of its evidentiary significance.
Please get in touch.