Skip to content
MDA-038 Mobile Devices & Apps

What is device encryption?

Device encryption protects stored data by making it unreadable without the correct key or unlock process.

What this means

On modern phones, encryption is usually built into the operating system and enabled by default.

The device may need a passcode, password, pattern or biometric unlock before protected data becomes available.

The state of the device matters.

A powered-off device, or one that has just restarted, may protect data more strongly because the user has not yet entered the passcode.

After the device has been unlocked, some data and encryption keys may remain available until it locks, restarts or loses power.

This is why switching off an unlocked phone can destroy an important access opportunity.

Some information may remain visible on the lock screen. Provider, cloud and linked-device records may exist elsewhere. Specialist methods may also be available depending on the device and software version.

The operational takeaway is: encryption controls access to stored data, not the value of the enquiry. Preserve the device state, avoid actions that strengthen the lock and pursue cloud, provider and linked-device evidence alongside specialist examination.

What to check or do next

  • Investigators should avoid casual passcode attempts, restarts, updates or power loss.
  • Record the device state and seek specialist advice where access may depend on preserving a live or unlocked condition.

Evidential limits

The key point is that possession of the handset does not automatically provide access to its contents.

Encryption does not mean that no evidence can be obtained.

Encryption protects data at rest. It does not necessarily prevent the user or applications from accessing data while the device is unlocked.

It also does not prove anything about who created the encrypted content.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.