What happens to evidence when a device restarts?¶
A restart can change a mobile device’s evidential state.
What this means¶
When the device powers back on, it may require the main passcode before most protected data becomes available.
Biometric unlock may be disabled until that passcode is entered.
Applications may close, temporary memory may be cleared and active sessions may end.
Some decrypted data or encryption keys available before the restart may no longer be accessible in the same way.
The device may also reconnect to mobile data, Wi-Fi, Bluetooth, cloud services and application providers.
That can create new records, trigger synchronisation or expose the device to remote commands.
System processes may update timestamps, run checks, complete pending installations or generate logs.
A restart can therefore both remove opportunities and create new changes.
Stored data normally remains on the device, but access may become more difficult and volatile information may be lost.
Where a restart occurs accidentally or through battery loss, record the time, circumstances and what was observed before and after.
Also consider evidence outside the device, including provider records, cloud backups and linked accounts.
The operational takeaway is: a restart may close active sessions, clear volatile data and strengthen device protection. Avoid restarting by habit and document any restart because it can materially affect access and interpretation.
What to check or do next¶
- If a device is already powered off, do not automatically turn it on.
- If it is powered on and unlocked, do not restart it merely to stabilise it or check whether it works.
Evidential limits¶
This does not mean every restart destroys all evidence.