Does a download record prove the file was opened?¶
No. A download record does not prove that the file was opened.
It shows that the cloud service recorded data being transferred to a device, browser, application or another service.
What this means in practice¶
A file may download automatically through synchronisation, backup, caching or browser behaviour. A user may start a download and never open it. An application may fetch the file in the background.
The provider may record a completed transfer, a request to download or the generation of a download link. Those are not always the same thing.
Then examine the receiving device where possible.
Use precise wording in reports. State that the service recorded a download or transfer and separately address whether there is evidence the file was opened.
What this may show¶
Investigators should establish how the service defines the event. Check whether the record includes file identifier, account, session, device or browser information, IP address, application and transfer outcome.
Device evidence may show the file path, creation time, application use, recent-file records, preview data or later opening. But local timestamps also require care because they may reflect synchronisation or copying.
What this does not show on its own¶
The dangerous assumption is that download equals viewing or reading.
A download to one device does not prove the account holder personally initiated it. The account may be shared, the session stolen or an application authorised to fetch files.
Equally, absence of a local copy does not prove the download did not occur. The file may have been deleted, stored elsewhere or streamed through a temporary location.
Key takeaway
A download record proves a transfer event, not that a person opened, read or understood the file; those conclusions require device and contextual evidence.