How Are Chat Logs and Emails Preserved for Court?
Introduction
Chat logs and emails can establish admissions, agreements, threats, instructions, payments, and other material facts in Philippine proceedings. Their usefulness, however, depends not only on what they say but also on whether the proponent can show that the electronic communications are authentic, complete, reliable, and properly preserved.
A screenshot or printed email may support a claim, but it can be challenged as incomplete, altered, unauthenticated, or hearsay. A sound preservation process should therefore begin as soon as litigation, an investigation, or a legal dispute becomes reasonably foreseeable.
The governing rules include the Rules on Electronic Evidence, the 2019 amendments to the Rules on Evidence, and relevant Supreme Court decisions concerning text messages and other electronic communications. The objective is to preserve the original electronic data and create a documented record showing how the evidence was collected, stored, examined, and presented.
What Rules Govern Electronic Communications?
The Rules on Electronic Evidence recognize electronic documents, electronic signatures, and electronic data messages as capable of being admitted in evidence when the applicable requirements on authentication, integrity, and proof are satisfied. The Rules also contain special provisions for ephemeral electronic communications, including text messages, telephone conversations, chatroom sessions, streaming audio, and streaming video.
The 2019 Amendments to the Rules on Evidence expressly recognize electronic, optical, and similar means of recording and presenting evidence. Electronic data may qualify as an original or equivalent evidence when the applicable requirements are met, and the court may consider the reliability of the manner in which the data was generated, stored, or communicated.
In [Asuncion v. Salvado (2022)](#J1.19), the Supreme Court explained that text messages are ephemeral electronic communications under Section 1(k), Rule 2 of the Rules on Electronic Evidence. The Court reiterated that such communications may be admitted when proven in the manner required by Section 2, Rule 11 of the same Rules.
In [Nuez v. Cruz-Apao (2005)](#J3.11), the Court accepted text messages where the recipient testified about their contents and personal knowledge, the sender admitted that the cellphone number belonged to her, and the parties had signed and attested to the accuracy of the messages. The Court also noted that technical rules are not applied with the same strictness in administrative cases.
Preservation Is Different From Authentication
Preservation means protecting electronic information from loss, alteration, overwriting, deletion, or destruction. Authentication means showing that the evidence is what the proponent claims it to be. A properly preserved file may still require testimony or other evidence identifying its source and explaining its contents.
For example, preserving an email in its native format may help establish its metadata and integrity. It does not automatically prove that the account holder personally sent the email. Evidence connecting the account, device, phone number, sender, or recipient to the communication may still be necessary.
Step One: Identify the Relevant Communications
Begin by defining the subject matter, persons involved, relevant accounts, devices, and date range. The preservation scope should be broad enough to capture related communications but sufficiently focused to avoid unnecessary collection of private or irrelevant material.
Identify whether the information exists in any of the following forms:
- SMS or text messages;
- messaging applications and chatroom conversations;
- email messages and attachments;
- social-media direct messages;
- voice messages, video messages, or call recordings;
- cloud backups and synchronized devices; and
- server-side records, subscriber information, and traffic data.
Record the reason for preservation, the persons who approved it, the date when the duty to preserve arose, and the categories of information covered. This record helps demonstrate that the collection was deliberate rather than selective or opportunistic.
Step Two: Issue a Preservation Notice
A preservation notice should instruct the relevant person, business unit, employee, service provider, or custodian not to delete, modify, reset, overwrite, or otherwise manipulate potentially relevant electronic information.
The notice should identify the accounts, devices, applications, date range, and types of information covered. It should also direct the recipient to suspend automatic deletion policies where legally and technically possible.
For evidence held by an internet service provider, law enforcement authorities may request preservation of computer data under the applicable cybercrime rules. Subscriber information and traffic data are generally preserved for at least six months from the transaction, while content data is preserved for six months from receipt of the preservation order. A one-time extension of another six months may be ordered.
These periods should not be treated as a substitute for prompt collection. A preservation order protects data from deletion for a period; it does not necessarily provide permanent access to the data or establish its authenticity.
Step Three: Preserve the Original Electronic Form
Do not rely exclusively on screenshots, photographs, or copied text. Preserve the communication in the form in which it was received or stored whenever possible.
For emails, collect the native message file and complete headers. Depending on the system, this may include formats such as EML or MSG. Preserve the sender and recipient fields, subject line, date and time, message identifier, routing information, attachments, and relevant header data.
For chat applications, preserve the available native export, account data, conversation export, media files, and system-generated timestamps. If the application does not provide a complete export, document the limitations and supplement the collection with a forensic image, screen recording, or other competent evidence.
For text messages, preserve the original handset or a forensic extraction where legally authorized and technically feasible. Retain the SIM card, device identifiers, account information, and available backup data when they are relevant to identifying the sender or recipient.
Step Four: Collect the Data Forensically
Collection should be performed by a person with appropriate technical competence. The collector should avoid changing the source device or account and should document each material step.
A defensible collection process commonly includes the following:
- Photograph or record the condition of the device, screen, connections, and relevant application.
- Record the device make, model, serial number, IMEI, operating system, account identifiers, and time settings.
- Document the date, time, location, collector, owner or custodian, and method of access.
- Use a validated forensic tool or an application-approved export method, where available.
- Collect related attachments, media, embedded links, and conversation context.
- Generate a cryptographic hash of each forensic image or exported file.
- Store the acquired data in secure, access-controlled media.
Collection methods must comply with applicable constitutional, statutory, contractual, and workplace restrictions. Unauthorized access to another person’s account or device may create separate civil, criminal, employment, or privacy issues.
Step Five: Preserve Metadata and Context
Metadata may reveal when a message was created, sent, received, modified, exported, or stored. It may also help identify the originating account, device, server, message identifier, or file history.
Preserve the entire conversation rather than isolated messages. A single screenshot may omit earlier statements, later clarifications, deleted-message notices, reactions, attachments, or indicators that a message was forwarded.
For emails, retain the full header and attachments. For chats, retain the conversation participants, usernames, phone numbers where displayed, timestamps, profile information, and relevant application-generated indicators. Record whether the time displayed by the device is synchronized or potentially inaccurate.
Step Six: Create and Maintain a Chain of Custody
A chain-of-custody log should identify every person who handled the source device, storage media, export, forensic image, or working copy. Each entry should state the date, time, person, purpose, action taken, and transfer details.
Maintain a distinction between the original source, the forensic image or native export, and any working copy used for review. Analysis should ordinarily be performed on a verified copy, while the original acquisition is stored securely and left unchanged.
Hash values should be recorded at acquisition and verified again before production or presentation. Any discrepancy should be investigated and explained rather than ignored.
Step Seven: Authenticate the Communications
Authentication may be established through testimony, admissions, account records, device evidence, surrounding circumstances, or other competent proof. The witness should explain how the communication was received, stored, identified, and preserved.
For emails, useful authenticating evidence may include testimony from the sender or recipient, business records, account ownership, correspondence history, distinctive content, reply chains, server records, or the sender’s conduct after transmission.
For text messages and chats, the recipient’s testimony may be important because the recipient is a party to the exchange or has personal knowledge of it. Evidence linking the phone number, account, device, or username to the alleged sender may further strengthen authentication.
In [Mabanag v. Ramos (2024)](#J4.17), the Court held that the complainant’s testimony as a party to the exchange was sufficient to prove the contents of text messages. Screenshots attached to a sworn complaint were considered together with the complainant’s positive identification and sworn statements, while the respondent’s general denial was insufficient to overcome that evidence.
Step Eight: Prepare an Affidavit of Evidence
An affidavit should explain the witness’s personal knowledge, technical competence, relationship to the account or device, and the manner in which the electronic communication was obtained and preserved.
The affidavit should identify:
- the source account, device, or application;
- the person who sent or received the communication, if known;
- the method used to collect or export the data;
- the preservation and storage procedures followed;
- the meaning of abbreviations, usernames, phone numbers, and timestamps;
- the attachments and related communications; and
- the hash values or other integrity checks, when applicable.
The Rules on Electronic Evidence permit matters concerning the admissibility and evidentiary weight of an electronic document to be established through an affidavit based on the affiant’s direct personal knowledge or authentic records. The affidavit must affirmatively show the affiant’s competence to testify on the matters stated.
Why Screenshots Alone May Fail
In [GJJ v. Easy Peso (2022)](#I1.15), the National Privacy Commission ruled that screenshots alone, without an affidavit authenticating and explaining their contents and the competence of the affiant, did not satisfy the requirement for admissibility and evidentiary weight in that administrative proceeding.
The decision illustrates an important distinction: a screenshot may be a useful demonstrative copy, but it may not be sufficient proof of the underlying electronic communication. The proponent should supplement it with testimony, an affidavit, native records, device evidence, account records, or corroborating evidence.
Where the screenshot is offered to prove that a third party received a message, the testimony or affidavit of that recipient may be necessary. Hearsay concerns may remain if the person presenting the screenshot has no personal knowledge of the communication.
Step Nine: Anticipate Common Defense Objections
| Objection | Recommended response |
|---|---|
| The message is unauthenticated. | Present testimony linking the communication to the sender, recipient, account, device, phone number, or surrounding conduct. |
| The screenshot was altered. | Produce the native export, forensic image, metadata, hash verification, complete conversation, and collection records. |
| The message is hearsay. | Identify the purpose of the offer, present the sender or recipient where appropriate, and establish a recognized exception or independent non-hearsay purpose when applicable. |
| The copy is incomplete. | Present the full conversation, attachments, message history, export report, and evidence explaining any missing data. |
| The account was not controlled by the alleged sender. | Present account ownership, device possession, login records where lawfully obtained, distinctive language, admissions, and corroborating conduct. |
| The evidence was illegally obtained. | Establish lawful consent, authority, discovery process, warrant, preservation order, or other valid legal basis for collection. |
Step Ten: Present the Evidence Clearly
Use the native electronic file or a properly authenticated copy as the evidentiary source. A readable printout or screenshot may be used as a presentation aid, but it should correspond to the preserved source and should not omit material context.
Prepare a witness who can explain the communication in plain terms. The witness should be able to identify the participants, account or device, date and time, manner of receipt, preservation process, and any relevant technical limitations.
If technical issues are disputed, consider presenting a qualified forensic examiner. The examiner should explain the acquisition tool, extraction method, hash process, chain of custody, and whether the analysis altered the source data.
Privacy and Confidentiality Considerations
Electronic communications may contain personal information, privileged communications, trade secrets, health information, or information concerning persons who are not parties to the case. Limit collection to relevant information and apply access controls throughout the process.
Redact irrelevant personal information when appropriate, but preserve an unredacted evidentiary copy securely if the complete record may later be required. Maintain confidentiality and comply with lawful orders governing discovery, inspection, production, and disclosure.
Preservation should also respect constitutional privacy rights and applicable data-protection obligations. A party should not assume that possession of a device or account password automatically authorizes unrestricted examination of all stored communications.
Typical Scenarios
Contract Dispute
An email exchange may show that the parties agreed on price, delivery, or revised terms. Preserve the full thread, attachments, headers, and subsequent conduct, rather than relying only on a cropped screenshot of one sentence.
Collection or Harassment Complaint
Text messages may establish repeated demands, threats, or disclosure of information to third parties. Preserve the complete message thread, the recipient’s device where possible, the phone number, dates, and any related call or payment records.
Employment Investigation
Workplace chats may show instructions, approvals, or misconduct. Establish the account ownership, company communication policy, access authority, and manner of collection. Avoid collecting unrelated private conversations.
Administrative Proceeding
Because technical rules may be applied less strictly in some administrative proceedings, electronic messages may still carry probative value through sworn testimony and corroborating circumstances. Nevertheless, a formal preservation and authentication process reduces the risk of exclusion or diminished weight.
Recommended Preservation Checklist
- Define the relevant persons, accounts, devices, applications, and date range.
- Issue a written preservation notice and suspend routine deletion where appropriate.
- Preserve native files, complete headers, attachments, metadata, and full conversation context.
- Use a qualified collector and document the collection method.
- Generate and verify hash values for forensic images and exported files.
- Maintain a complete chain-of-custody record.
- Prepare affidavits from persons with personal knowledge and appropriate competence.
- Securely retain the original acquisition and analyze only verified working copies.
- Corroborate disputed communications with account, device, payment, server, or conduct evidence.
- Review privacy, privilege, consent, and lawful-access issues before production.
Conclusion
Chat logs and emails are more likely to withstand defense objections when the proponent preserves the original electronic form, captures metadata and context, documents the collection process, verifies integrity, and presents a competent authenticating witness.
The safest approach is to treat electronic communications as evidence from the moment a dispute becomes foreseeable. Screenshots may assist the court in reading the material, but native records, forensic documentation, sworn testimony, and corroborating evidence provide the stronger foundation for admissibility and evidentiary weight.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

