Preserving Digital Evidence in Colorado: The First Steps That Decide What You Can Prove
A well-meant cleanup can cost the case. How Colorado's evidence rules and Aloi v. Union Pacific shape preserving phones, email and files before litigation.
Most of the digital evidence problems we see were created before anyone called a lawyer. A manager wipes a departing employee's laptop for the next hire. A phone is traded in for an upgrade. An email retention policy keeps deleting, on schedule, the messages a dispute will turn on.
None of that is malicious. All of it can cost a case. This is what Colorado law expects, and what to do in the first days, before a forensic examiner is involved.
When the duty to preserve starts
The Colorado Supreme Court's leading decision on destroyed evidence is Aloi v. Union Pacific Railroad Corp., 129 P.3d 999 (Colo. 2006). The court upheld an adverse-inference instruction, which tells the jury it may assume the destroyed evidence would have hurt the party that destroyed it. Its reasoning was that such an instruction "will deter parties from destroying evidence that they know or should know will be relevant to litigation."
The railroad in Aloi had a routine records schedule, and it was on notice before those records were discarded. The schedule didn't protect it. The lesson for any business is simple. Once you know, or should know, that something will matter in a dispute, routine deletion has to stop for that material.
What a Colorado court needs to see
Under CRE 901(a), evidence is authenticated by "evidence sufficient to support a finding that the matter in question is what its proponent claims." For digital evidence, that means showing the file you offer is the file that existed, unchanged.
Forensic work almost always happens on copies, not originals, and Colorado's best-evidence rules accommodate that. A "duplicate" includes a copy made "by mechanical or electronic re-recording … or by other equivalent techniques which accurately reproduce the original" (CRE 1001(4)). A duplicate is admissible like an original unless "a genuine question is raised as to the authenticity of the original" or admitting it would be unfair (CRE 1003).
That is where a forensic image and its hash value earn their keep. A hash taken at acquisition and checked again later shows that the copy still matches what was collected.
Colorado is not federal court
This is a difference worth knowing. The Federal Rules of Evidence let a party self-authenticate data copied from a device with a written certification of the hash-verification process (FRE 902(14)). Colorado's rules do not include that provision: Rule 902 of the Colorado Rules of Evidence ends at (12), as reprinted in the Colorado Supreme Court's January 2025 rule change. Check the current rules before relying on this in a filing.
In practice, in a Colorado state court, plan on a witness who can explain how the copy was made and verified. In federal court in Colorado, the certification route may be available. Either way, the process has to be documented from the first minute. That is why the first person to handle the evidence matters.
What to preserve, source by source
- Phones. Do not factory-reset, trade in or "clean up" the device. Keep it charged, and keep it away from networks so it can't be wiped remotely. Then call an examiner. Message apps with disappearing-message timers keep deleting while you wait.
- Computers. Do not reimage, reassign or "just take a look around." Opening files and browsing folders changes timestamps an examiner may need. Unplug from the network if you suspect ongoing misuse, but don't run cleanup tools.
- Email and cloud accounts. Suspend deletion policies for the people involved and place holds where your platform supports them. Default retention windows are short. We explain them in what Microsoft 365 and Google Workspace actually keep.
- Shared drives and business systems. Export logs and audit trails before they roll over. Many systems keep them for a limited time.
- Camera systems. Many DVRs record on a loop and overwrite the oldest footage. Export the relevant window now, and note the device clock against real time.
Chain of custody, in plain terms
Chain of custody is a written answer to four questions: who had the evidence, when, where it was kept, and what was done to it. Start it the moment something is set aside. Write down the date, the time, the person and the condition, even on paper. A professional acquisition adds hash values and a documented process. A gap you can explain is survivable. A gap nobody wrote down is what gets argued about.
Where we fit
Our digital forensics work begins with preservation: forensic images of computers and phones, collection from Microsoft 365 and Google accounts, hash verification, and a custody record from the first handoff. We also built an air-gapped evidence platform for a legal services firm, with hashing at every step of intake and custody logs ready for deposition. When a case needs testimony, see do you need a digital forensics expert witness in Colorado.
Frequently asked questions
Can't we just copy the files ourselves? You can, but an ordinary copy changes metadata, carries no hash from the source, and makes the person who did it a potential witness. If the files may matter in a dispute, have them collected properly once.
Do we need to image every device? Not usually. Preservation should be proportional: identify the people and systems that matter, preserve those properly, and suspend deletion everywhere else that is relevant.
The data is already deleted. Is it gone? Often not entirely, but it depends on the device, the storage and how much has been written since. The sooner the device stops being used, the better the odds.
This article is general information about Colorado evidence rules and case law, current as of October 2026. It is not legal advice. Preservation obligations in a specific matter are for your attorney to define.
Need something preserved now? Contact us.