Skip to content
LOG-061 Logs, Records & Provider Evidence

Could daylight-saving changes affect a timeline?

Yes. Daylight-saving changes can make a timeline appear to contain a missing hour, a repeated hour or events in the wrong order.

The effect depends on how each system stores and displays time.

Avoid this assumption: That every local clock moves smoothly forward without repetition or omission. It does not.

When clocks move forward, one local hour does not occur. When clocks move back, one local hour occurs twice. A timestamp such as 01:30 may therefore be impossible on one date or ambiguous on another.

Systems storing UTC usually avoid that ambiguity internally. Problems arise when UTC is converted to local time, when devices store local time directly or when exports remove the offset information.

Two events with the same displayed local time may have occurred an hour apart. An event that appears later by local clock value may actually have occurred earlier in absolute time.

Investigators should identify whether the source stored UTC, local time or an explicit offset. Check whether the relevant date fell near a daylight-saving transition in the applicable jurisdiction.

Preserve the original timestamp and offset. When converting, use a recognised time-zone rule for the date and location. Do not apply the current offset to an older event without checking.

If a time falls within a repeated hour, report the ambiguity unless another field or reliable reference resolves it. Correlate with UTC-based logs, network records, CCTV or other independent evidence.

Operational takeaway

Daylight-saving changes can create missing, repeated or ambiguous local times, so timelines near a clock change must preserve offsets and use date-specific conversion rules.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.