A screenshot may document a threat, an admission, a transaction or a public post. It may also have been cropped, altered, removed from its context or obtained through unlawful access. A recording may reproduce the words spoken accurately while the act of recording it, or the way it is later used, still creates criminal and procedural risk. The right question is therefore not, “It is on my phone, so can I file it in court?” but: “How was it obtained, what does it actually prove, is it authentic, and may it be used in this particular case?”
The short answer
Courts do not treat every digital file in the same way. A message received by its intended recipient, a public social-media post, an email preserved with its technical data and a covert recording are governed by different rules. Lawful acquisition comes before evidential value. A legal claim does not automatically cure unlawful interception, unauthorized entry into another person’s account or a prohibited recording.
1. Four separate tests for the same file
Discussions about digital evidence often merge four distinct questions. A file may be genuine but unlawfully obtained. It may have been obtained lawfully yet fail to prove what a party alleges. It may be relevant, but filing it in full may disclose unrelated personal data concerning third parties. Finally, a court may admit it without giving it decisive weight.
- Lawful acquisition: were you entitled to access the message, account, device, call or website?
- Permissible use: may this material be used in the particular civil, criminal, administrative or family dispute?
- Authenticity and completeness: can it be established who created it, when, in what context and whether it was edited?
- Necessity and proportionality: is the whole file required, or would a narrower extract prove the point without unrelated disclosures?
Article 19 of the Constitution of Greece protects the secrecy of communications and prohibits the use of evidence obtained in breach of communications secrecy, private life and personal-data protection. Procedural rules and case law develop that starting point. There is no reliable general rule that “anything which reveals the truth is allowed.”
2. Messages and screenshots: the recipient is not the same as a third party
Greek case law treats an SMS and a photograph of a screen as a mechanical representation and an electronic document. In Supreme Court of Greece decision 1141/2025, the Court accepted that a sender knows the message will be stored on the recipient’s device and may later be retrieved by that recipient. This explains why the intended recipient’s position differs materially from that of a third party who obtained the message without authority.
That distinction is not a blank cheque. Even a lawful recipient must connect the message to the fact in dispute and limit its use to what is necessary. If a conversation contains health data, family details, photographs of children or information about unrelated people, indiscriminately filing or circulating the entire thread may create additional legal issues.
When the screenshot comes from someone else’s account
Supreme Court decision 352/2026 is a particularly clear warning. The case concerned unauthorized access to another person’s online accounts, screenshots of private messages and the subsequent production of those screenshots in civil and criminal proceedings. The appeal against conviction was dismissed. The practical point is that invoking a need for evidence in court does not, by itself, authorize entry into another person’s email, cloud storage, profile or phone.
Critical boundary
Knowing a password, finding a device in the home or having an old shared login does not necessarily give you the right to open and copy an account. Authorization must be genuine, current and cover the particular access in question.
A screenshot does not authenticate itself
A screenshot shows what appeared on a display at a particular moment. On its own, it does not prove that the profile truly belongs to the named person, that earlier messages were not deleted, that the device clock was correct or that the image was not edited. The other party may challenge authenticity, completeness or attribution. The original on the device, the complete thread, an official platform export, technical data and, where needed, expert examination then become important.
3. Social media: public posts, stories and private messages
Facebook, Instagram, TikTok, X, LinkedIn, YouTube and online forums generate different categories of digital material. A post on a public profile is generally easier to record lawfully than a direct message or a story visible only to a restricted audience. Public accessibility does not, however, remove personal-data, image, personality or copyright protections.
Evidence should show its context: the account name and identifier, the URL where available, date and time, the complete text, preceding and following posts where they affect meaning, and how the content was accessible. For a story or live stream, a continuous screen recording that shows navigation from the profile to the disputed item may help establish context. It does not cure unlawful access or automatically prove who controlled the account.
- Public post: preserve the URL, account, date, full content and visibility; do not rely on a cropped quotation.
- Story or disappearing content: preserve a continuous record of lawful viewing and immediately note when and how it was accessed.
- Private message sent to you: retain the full conversation and the original in your own account, not only one sentence.
- Private message between third parties: do not enter another person’s profile, device or backup; an unlawful source can turn the supposed evidence into a risk for you.
- Reposting as pressure: do not publish private messages to shame or coerce the other person. Controlled use in proceedings and public exposure are entirely different acts.
The Hellenic Data Protection Authority warns that publishing information, photographs or videos about other people can have serious consequences and advises against doing so without approval. A screenshot useful to a lawyer or court is therefore not automatically safe to publish on social media at the same time.
4. Email, websites, cloud services and other digital sources
An email is more than the image displayed in an inbox. The original message may contain routing headers, a Message-ID, transmission details and attachments. Forwarding it or taking a screenshot removes much of that information. Where possible, preserve the message in its native location and export a copy, such as an EML file, without deleting the original. Headers assist technical assessment, but do not by themselves identify the natural person who pressed “send.”
For websites and online registers, record the exact address, access time, page title and, where relevant, the PDFs or terms that applied at that time. A simple screenshot may omit both the address and the rest of the text. Saving the page as a PDF, recording the navigation and retaining the original downloaded file can supplement the record. For critical or fast-changing pages, a lawyer may recommend formal recording or technical expert assistance.
Cloud files, shared documents and version history
Google Drive, OneDrive, Dropbox, corporate systems and collaboration applications often retain versions, event logs or sharing permissions. Those records may be more informative than a screenshot of the document. Preserve the original format, filename and download date and, where your own account permits it, the version history. Do not bypass access controls or use former corporate credentials after your authorization has ended.
What a hash actually proves
A cryptographic file hash, such as SHA-256, can show that a particular copy has not changed since the hash was calculated and recorded. It does not prove who created the file, whether its content is true or whether it had already been altered before the calculation. A hash is an integrity tool, not a certificate of truth.
EXIF, photographic metadata and signs of alteration
A digital photograph may contain EXIF and other metadata: device maker and model, capture date and time, orientation, camera settings, dimensions, an embedded thumbnail and, if enabled, location data. It may also identify editing software or a later save time. These fields can support technical hypotheses about a file’s origin and history; standing alone, they do not prove who took the photograph, where that person actually was or whether the depicted scene is genuine.
Metadata may be absent, changed or stripped when an image is sent through a messaging application, uploaded to a social network, exported from editing software or saved again. Missing EXIF does not prove fabrication, and apparently consistent EXIF does not authenticate an image. Even a plausible timestamp or familiar phone model must be considered with the original file, the device, the originating account and the surrounding facts.
Where fabricated or altered material is suspected, technical examination does not depend on a single field. It may consider file structure and format, metadata inconsistencies, differing compression traces, embedded thumbnails, dimensions and encoding, continuity of video frames or audio, version history, application and cloud logs, and the chain of acquisition and custody. Some interventions leave detectable inconsistencies; others may not support a reliable conclusion. It is therefore inaccurate to say that every alteration always leaves a trace, or that an automated tool alone can establish forensic certainty.
If you suspect fabricated evidence
Do not resave the file, pass it through applications that alter its structure or metadata, or conduct your own tests on the only copy. Preserve the original medium and document the lawful route by which it was acquired. Ask your lawyer whether an independent technical adviser or court expert is needed. Deliberately creating or falsifying digital material does not strengthen a case: it can destroy the producer’s credibility and create separate legal risks.
5. Covert recording: the most dangerous misconception
A common claim is: “Because I am taking part in the conversation, I may record it.” Article 370A of the Greek Penal Code and Supreme Court decision 750/2025 point in the opposite direction. Recording a telephone communication or a non-public oral conversation with another person without that person’s express consent may be a criminal offence even when the person making the recording is a participant. Improper use of the recording is also treated separately.
Case law contains exceptional balancing exercises for protecting overriding legal interests or proving particularly serious events. They are not a general permission and should not be assessed by a citizen only after pressing “record.” Supreme Court decision 382/2024 restates the rule excluding, in criminal proceedings, evidence obtained through criminal acts. Fear, a dispute or a difficult conversation does not by itself make the recording lawful.
Before pressing record
If you believe you are being threatened or blackmailed, or need proof, first seek specific legal advice and consider lawful alternatives: written communication, a witness, a formal report to the authorities or another permitted method of documentation.
The narrow exception for business calls
Recording professional communications to prove a commercial transaction or another business communication may be permitted under the specific conditions of Article 4(3) of Greek Law 3471/2006. The Hellenic Data Protection Authority emphasizes prior notification and the necessity of recording for the stated purpose. The exception does not cover every business call indiscriminately and does not turn a personal or family conversation into a professional one.
Voice notes and video messages
An audio message that the sender deliberately chose to send and store in the recipient’s account is factually different from a covert recording of a live call. Lawful possession, authenticity, relevance and proportionality must still be examined. Publicly posting a private voice note may raise a different problem from producing it on a restricted basis to a lawyer or court.
6. How digital material can turn against the person holding it
- Unauthorized access: opening another person’s phone, email, cloud storage, social profile or backup without valid authorization.
- Covert recording: recording a telephone or private conversation without express consent on the mistaken assumption that participation is enough.
- Alteration or selective presentation: cropped messages, a changed order, concealed dates, removed names or edited audio.
- Fabricated digital evidence: composing an image or conversation, changing metadata or creating a misleading file intended to appear authentic. Apart from technical challenge, this can decisively damage credibility and generate separate legal issues.
- Public exposure: posting private messages, photographs or recordings on Facebook or in a group where the legitimate purpose could have been served through limited use in proceedings.
- Threatening publication: using material to pressure, intimidate or coerce rather than as controlled evidence.
- Destroying the original: deleting the conversation or file after taking a screenshot and losing the best material for authenticity checks.
- Breach of confidentiality: uncontrolled sharing with friends, groups or unauthorized colleagues, particularly where health data, children or professional secrecy are involved.
- Overstated technical certainty: claiming that a filename, EXIF field, screen time or hash proves more than it actually can.
7. A practical preservation protocol
The objective is to preserve material as found, record its origin and restrict access. A citizen does not need to act as a forensic examiner. The priority is not to destroy, alter or distribute the item before an appropriate professional assesses it.
- Stop editing. Do not crop, add arrows or write on the only copy, and do not repeatedly convert the file.
- Keep the original. Preserve the device, your own account, the conversation, original email or primary file in its native location.
- Record the context. Note when, where and by what lawful route you saw or received it, who was present and what preceded it.
- Capture the full path. For social media or a website, show the profile, URL, date, visibility and then the disputed content. For a conversation, retain enough preceding and following text.
- Use the service’s export where permitted. Keep EML and headers for email, an official chat export, and the original cloud format with available version history.
- Create a secure copy. Store a read-only copy with controlled access. If a hash is calculated, record the date, tool and exact file that was checked.
- Do not continue accessing. If the item appeared accidentally on someone else’s device or account, do not search further. The next action may change the legal assessment.
- Give your lawyer a restricted copy. Explain precisely how it was obtained and do not conceal inconvenient technical or factual details.
- Act promptly in cases of fraud, threats or blackmail. Preserve links, usernames, emails, files and history, and use official reporting routes without provoking further contact to obtain a “confession.”
What not to do
Do not ask a friend to enter an account, install monitoring software, guess a password, impersonate another person or publish the material “so it will not disappear.” Safe preservation does not require a new unlawful act.
8. How authenticity is assessed
Authenticity is a chain of indicators, not a single magic technical field. A court may consider the originating device or account, continuity of the conversation, style of expression, independent events, technical data, witness testimony and expert findings. In a fraudulent email, for example, the displayed sender name may mislead, while the full headers and comparison with other communications provide a more useful picture.
Confirmation by an independent professional that a page or conversation appeared in a particular form at a particular time may strengthen proof of what was observed. It does not automatically establish who created the account, who operated the device or whether the entire history is complete. Where the dispute is serious, the lawyer should decide whether a technical adviser, expert witness or formal request to a provider or authority is required.
Edited images, synthetic voices and deepfakes
The ability to create convincing false images, video and voices makes original files and context increasingly important. A viral video or audio file received through a third party should not be treated as genuine merely because it “looks real.” The earliest available source, an unbroken history of the file, independent confirmation and technical examination should be sought. Automated detection tools may provide indicators, not a final forensic answer.
9. Quick risk table
| Digital source | What should be examined | Practical assessment |
|---|---|---|
| SMS or chat received by you | Lawful possession, full thread, relevance, proportionality and authenticity. | Often potentially usable, but not automatically sufficient. |
| Screenshot from another person’s account | Authorization, method of acquisition, Article 370E of the Greek Penal Code and Article 19 of the Constitution. | High legal risk. |
| Public social-media post | URL, public visibility, time, account identity and complete context. | Easier to record lawfully, but not free to republish. |
| Private story or direct message | Who was entitled to access it, visibility settings, full content and personal data. | Highly dependent on who viewed it and how. |
| Original EML, complete headers, attachments and continuity of correspondence. | Stronger than a screenshot when the native form is preserved. | |
| Covert call recording | Express consent, Article 370A of the Greek Penal Code, specific circumstances and permitted use. | High criminal and procedural risk. |
| Business call recorded after notice | Specific purpose, prior notice, necessity and secure retention. | Only within the narrow statutory exception. |
| Voice note sent to you | Lawful receipt, authenticity, content and restricted use. | Different from covert recording, but not without limits. |
| Photograph, edited crop or repost | Original file, device, EXIF and other metadata, thumbnail, structure, context and editing history. | Useful indicators, not independent proof of authenticity. |
| Cloud or version history | Access rights, native format, timestamps, logs and permission changes. | Useful when collected through an authorized account. |
This table is an initial risk-assessment aid. It does not replace analysis of the particular case and the applicable procedure.
10. Frequently asked questions
Is one screenshot enough to win a case?
No. It may be evidence, but its value depends on lawful origin, authenticity, full context, connection with the fact in dispute and the remaining evidence. A printout of one sentence without the device, conversation or technical data is easier to challenge.
May I record someone who is threatening me?
Do not assume that the seriousness of the incident automatically permits recording. Article 370A of the Greek Penal Code remains central, and exceptions are narrow and fact-sensitive. Obtain prompt legal advice and, where there is danger or suspected crime, contact the competent authorities. Safer and lawful methods of documentation may be available.
What if the sender deleted the message?
Do not try to enter the sender’s account. Preserve what lawfully remains on your device or in your account, any notification, a backup you are entitled to use and the chronology of the incident. A lawyer can assess whether formal action toward a provider or authority is needed and whether the data may still be available.
May I post the messages on Facebook to prove that I am telling the truth?
Public posting is not the same as controlled production to a lawyer or court. It may infringe personal data, personality rights, image rights or confidentiality and expose unrelated third parties. The safer course is not to publish the material before legal assessment.
Does a public post prove who wrote it?
At most, it initially shows that particular content appeared on an account when it was captured. Attribution to a natural person may be disputed by alleging a fake profile, account compromise or third-party management. Supporting indicators and, in a serious dispute, technical examination may be required.
If the material is true, does that cure an unlawful method of obtaining it?
Not automatically. The truth of the content and the lawfulness of acquisition are different questions. Constitutional and procedural protection would lose its purpose if every unauthorized access became permissible merely because something relevant was eventually found.
11. The safe conclusion
Digital evidence is powerful because it records words, images, times and routes. It is also fragile because it can be copied, cropped, altered and obtained incorrectly with ease. A person protects their case most effectively not by gathering as much material as possible, but by stopping in time, preserving the original, recording the source honestly and obtaining legal advice before any further access, recording or publication.
Legal notice
This article provides general information and is not individualized legal advice. The answer depends on the method of acquisition, type of proceedings, content, persons involved and intended use. Before making a covert recording, accessing an account, publishing material or filing sensitive evidence, seek advice from a lawyer who knows the actual facts.
Official sources and case law
- Constitution of Greece, Article 19. Secrecy of communications and the prohibition on using evidence obtained in breach of Articles 9, 9A and 19.
- Supreme Court of Greece 1141/2025. SMS messages and screen photographs as mechanical representations, distinguishing the recipient from a third party and weighing necessity and proportionality.
- Supreme Court of Greece 352/2026. Unauthorized account access, capture of private messages and later use of screenshots in legal proceedings.
- Supreme Court of Greece 750/2025. Application of Article 370A of the Greek Penal Code to recording telephone communications or non-public conversations without express consent and to use of the material.
- Supreme Court of Greece 382/2024. Article 177(2) of the Greek Code of Criminal Procedure and exclusion of evidence obtained through criminal acts, subject only to exceptionally narrow balancing.
- Hellenic Data Protection Authority: recording telephone conversations. The narrow exception in Article 4(3) of Law 3471/2006 for professional communications, requiring prior notice and necessity.
- Hellenic Data Protection Authority: publishing data on social networks. Risks arising from publication of information, photographs, videos and content concerning other people.
- Regulation (EU) 2016/679, Articles 5, 6 and 9. Lawfulness, purpose limitation, data minimization, security and processing for the establishment, exercise or defence of legal claims.
- Gov.gr: reporting cybercrime. The online report records what happened, where, when and how, and may include relevant evidence.
- Hellenic Cyber Crime Division: guidance. Practical preparation of an incident chronology and useful digital material for reporting to the authorities.
- CIPA: About Exif 3.0. Official overview of the Exchangeable image file format and metadata that may be embedded in digital images.
- SWGDE: Best Practices for Image Authentication, version 2.0. Image authentication considers file structure, metadata, provenance, content and methodological limitations together.
- NIST/OSAC: Standard Guide for Forensic Digital Image Management. Preservation of originals and processed copies with transparency, integrity, security and availability.
Sources checked on 4 August 2026.
Photo: cottonbro studio / Pexels. Used for illustration.
Comments
Share your thoughts about this article.
No comments yet. Be the first to comment.
Submit a comment