Photographic evidence
Does a photograph have legal value?
A photograph counts until someone challenges it — and challenging it is cheap. What it actually takes for a photo to survive a dispute: trusted date, integrity and provenance.
The question almost always comes too late: after the fact, with the photo already sitting in a phone. And the honest answer is uncomfortable: a photograph holds up until someone challenges it. The moment the other side raises a hand, its value depends entirely on how hard it is to dismantle.
The mechanism: evidence until contested
Across European legal systems the treatment differs in detail but converges on one principle: a photograph is a representation of a fact, not the fact itself. It is generally accepted as evidence of what it depicts — and it can be contested by the party it is used against. Contesting it does not require proving forgery: it requires putting forward specific reasons why the reproduction does not match reality.
That threshold matters in both directions. A purely formulaic objection generally will not do — so the challenge is not costless. But once a substantiated challenge is made, the photograph typically stops carrying its full weight on its own and becomes one element among others, to be weighed alongside whatever else is available.
The problem with a photograph is not that it is weak. It is that challenging it costs far less than defending it — and defending it falls to you.
Once challenged, the burden shifts back to you. And at that point you need three things an ordinary photo does not carry.
The three things a photo does not prove
1. The date
A capture timestamp is written by the device clock, and the device clock is set by whoever holds the device. Changing the system date, taking the shot and setting it back is a thirty-second operation that leaves no obvious trace. A date you gave yourself is not a fact — it is a claim.
2. Integrity
That the file has not been altered since capture is unprovable unless you have a reference to compare it with. Without a fingerprint computed at a defined moment and preserved somewhere, there is no «before» against which to measure the «after».
3. Provenance
Who captured it, with which device, where. This is exactly the information metadata can carry — and precisely for that reason, anyone can write it to taste. See the guide on what EXIF metadata actually proves.
Why «certified photo» apps do not solve it
Dozens of apps stamp date, time and coordinates onto the image. They are useful as reminders. As evidence they add nothing, for a simple reason: that stamp is generated by the same device that could have faked it. Overlaying a date on an image does not prove the date — it proves someone wrote a date.
The step change happens when the critical information stops coming from you: when the date is certified by an independent third party, and integrity can be verified by anyone without asking permission.
What it actually takes
A cryptographic fingerprint (a hash: a string that changes completely if even one byte of the file changes) computed at the moment of capture. It answers one question, but definitively: is this file still identical to the one from back then?
A date that is not yours. A timestamp under the RFC 3161 standard, issued by an external authority, attests that the fingerprint already existed at that instant. It does not certify content — it certifies anteriority. Which is exactly what you need against the most common accusation: that you photographed later. See why a phone clock proves nothing.
Under eIDAS Regulation (EU) 910/2014, a qualified electronic timestamp issued by a qualified trust service provider enjoys a presumption of accuracy of the date and time it indicates, and of the integrity of the data it is bound to (Art. 41). An ordinary RFC 3161 timestamp is technically sound but does not carry that presumption — a distinction worth keeping straight.
A signature binding media, fingerprint and device into one coherent object, so that pieces from different acquisitions cannot be recombined.
A verifiable package. All of the above in a documented, standard container that anyone can open and check with common tools — ten years from now, without the software of whoever produced it.
The part almost nobody says
No tool — LOCUS included — can guarantee admissibility. Admissibility and evidential weight are assessed by the court, case by case, looking also at procedural chain of custody, the operator's standing and compliance with procedural rules. Anyone promising «guaranteed legal validity» is selling something that does not exist.
There is a second, equally honest limit: sealed evidence proves that those bytes existed at that instant and have not been touched since. It does not prove the depicted scene is genuine. Someone with access to the device before sealing can seal a staged scene. No cryptography fixes that — context, coherence and operator accountability do.
What a technical chain of custody gives you is narrower and far more useful: it turns a question of word against word into a question that can be checked. It does not ask anyone to believe you — it supplies the object on which the check is performed.
What changes in the courtroom
This is the difference that actually matters, and it is worth stating concretely. Faced with an ordinary photograph that has been challenged, a court has nothing to examine: it can only weigh competing assertions, or appoint an expert who will most often be able to say only that there is nothing on which to base a conclusion.
Faced with a sealed package, there is an object to examine. The judge can check it personally, opening the verification page in a browser or the interactive verification file that travels inside the package itself. If a court-appointed expert is instructed, they have far more: they can rebuild the bundle from scratch, recompute the fingerprint of every single file, compare each against the ones signed in the manifest, walk through the capture logs, and verify the timestamps against the issuing authority's public CA and the manifest signature.
The outcome of that check is not a matter of opinion: the fingerprints either match or they do not, the timestamp is either valid or it is not. There is no room for an expert report concluding «it cannot be established» — the most common, and least useful, outcome when an isolated photograph is examined.
It is also why the verification tools travel inside the package and rely on standard system commands: whoever checks does not have to install our software, does not need a connection, and does not have to trust us.
In practice
If you are documenting something that could end up in a dispute — damage, a site condition, goods at loading — the right question is not «is this photo any good?». It is «if someone challenges it, what will they have to examine?». If the answer is «nothing», you have a problem that can only be solved before the shutter, never after.
That is what LOCUS is for: it seals photos, video and audio at the moment of capture and produces a package anyone can verify independently — the opposing party included, even offline. The step-by-step is on the how to validate a bundle page.