Does copying data prove malicious intent?¶
No. Casework, backup, analysis, migration, handover and remote work can all require copying. The destination, authority, selection and later use - not size alone - determine its evidential meaning.
Explain the copy event¶
Identify source data, destination, account, process, time, approval and business purpose. A large authorised export may be routine; a small targeted copy can be significant.
Synchronisation or backup may continue automatically after a person enables a service or selects a folder. Separate that initiating decision from each later automated transfer while preserving responsibility for the setup where supported.
Build evidence of purpose¶
Personal storage or removable media can breach policy without proving a plan to steal or harm. Examine communications, concealment, retention, sale, disclosure or later use.
Deletion or movement after copying may support improper purpose, but legitimate cleanup and policy compliance remain alternatives to test. State copying, authority breach and malicious intent as separate conclusions.
Key takeaway
Treat copying as an action requiring explanation and infer malicious purpose only from destination, authority, concealment, communication and later use.