Skip to content
LOG-058 Logs, Records & Provider Evidence

Why does the time zone matter?

The time zone matters because the same moment can be displayed as different clock times in different locations or systems.

A log showing 14:00 may represent 14:00 local time, 14:00 UTC or a time converted for the person viewing the dashboard.

Avoid this assumption: That a timestamp can be understood correctly without knowing its time zone. It cannot.

An event recorded at 14:00 UTC would appear as 15:00 in the United Kingdom during British Summer Time. If one log uses UTC and another uses local time, the apparent sequence may be wrong by an hour or more.

Cloud platforms often store time in UTC but display it in the viewer’s local zone. Devices may store local time directly. Exports may convert time again or remove the original zone indicator.

The time zone can also affect dates. An event close to midnight may appear on different calendar days depending on the zone used. That can create apparent contradictions with witness accounts, CCTV or other records.

Investigators should preserve the original timestamp exactly as supplied, including any zone indicator or offset. Ask what zone the source system used and whether the export or dashboard performed a conversion.

When converting times, record the original value, original zone, converted value, target zone and method used. Consider daylight-saving rules that applied on the relevant date.

Do not label a time as local, UTC or exact merely because that seems likely. The system documentation or configuration should support the conclusion.

Operational takeaway

A timestamp without a confirmed time zone can be misunderstood by hours or even placed on the wrong date, so the original zone and any conversion must be preserved and explained.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.