One of the most common assumptions in digital investigations is also one of the most consequential: that deleted data is gone. It is not. The deletion of a file on a modern computer or mobile device does not, in most cases, result in the immediate or complete destruction of the data that file contained. It removes the file’s entry from the directory, making the space it occupied available for reuse, but the data itself typically remains on the storage media until it is overwritten by new data.
This property of digital storage is one of the most powerful tools available to digital forensic investigators. It means that employees who delete files to conceal their activity, individuals who attempt to erase evidence of misconduct, and organisations that try to conceal information from regulators or litigants are frequently unsuccessful. The investigator who examines the storage media at the right time, using the right tools, can often recover what the user believed they had destroyed.
Is Deleted Data Really Gone?
When a file is deleted through a standard operating system process — by moving it to the recycle bin and emptying it, or by deleting it directly — the operating system removes the file’s directory entry and marks the space it occupied as available for reuse. The data in that space is not changed. It remains on the storage media until it is overwritten by new data.
The practical consequence is that recently deleted files can often be recovered in their entirety. Older deleted files may be partially recovered, with fragments of data remaining in unallocated space even after some overwriting has occurred. And a significant amount of data that a user may not think of as ‘a file’ — fragments of documents opened in applications, thumbnail cache images of photos, temporary files created by operating systems and applications — is retained on the device beyond the point at which the user closed the application or deleted the document.
Digital Recovery Techniques
File carving: a technique that searches the raw binary content of storage media for the signatures associated with specific file types — the header and footer bytes that identify a JPEG, a PDF, a Word document, or a database file — and reconstructs files from those signatures regardless of whether the directory entry still exists. File carving is one of the most productive recovery techniques for deleted documents and images.
Unallocated space analysis: systematic analysis of the storage media’s unallocated space — the areas not currently allocated to any live file — for data fragments, complete deleted files, and other residual content. Unallocated space is the primary recovery environment for deleted files and contains a significant amount of recoverable data in most devices that have not been forensically wiped.
Volume shadow copy analysis: on Windows systems, Volume Shadow Copies are automatic backup snapshots of the file system taken at regular intervals. These snapshots preserve versions of files as they existed at earlier points in time, allowing the recovery of files that have been modified or deleted since the snapshot was taken.
Slack space analysis: file slack is the unused space between the end of a file and the end of the allocation unit in which it is stored. Slack space may contain fragments of data from files that previously occupied the same allocation unit, and analysis of slack space can recover content from files that have been fully overwritten at the directory level.
Registry and artefact analysis: the Windows Registry and various operating system artefacts — the Shellbag artefacts that record folder navigation history, the RecentDocs and UserAssist artefacts that record application and document usage, the Windows.edb search index that records file content — retain evidence of file activity even after the files themselves have been deleted.
Types of Recoverable Evidence
Deleted documents: Word documents, spreadsheets, PDFs, and other office documents deleted from the file system but recoverable from unallocated space or volume shadow copies. Particularly significant in IP theft and fraud investigations where documents have been deleted to conceal their contents.
Deleted emails: emails deleted from the email client but recoverable from the device’s PST or OST file, from database structures on mobile devices, or from server-side logs that are not under the user’s control.
Browsing history: internet browsing history stored in browser databases and cache files, recoverable from unallocated space even after the browser’s history has been cleared. Different browsers use different storage formats, and forensic analysis tools can parse all major browser database structures.
Deleted images and videos: photographs and videos recovered from unallocated space using file carving techniques, with the embedded metadata — date, time, and location of capture — intact where the file has been recovered completely.
Application data: data stored by applications in their own database structures, which may retain information about activity that the application’s visible interface does not expose. Messaging application databases, for example, often retain message content and metadata even after messages have been manually deleted within the application.
Limitations
Digital recovery has genuine limitations that a forensic investigation must acknowledge honestly. The primary limitation is overwriting: once the space occupied by deleted data has been overwritten by new data, the original content is typically irrecoverable. The likelihood of overwriting increases with the passage of time, the amount of new data written to the device, and the storage technology used.
Solid-state drives (SSDs) present specific challenges. Unlike traditional hard drives, SSDs use a process called wear levelling that distributes writes across the storage media in ways that do not preserve deleted data in predictable locations. Some SSDs also implement TRIM commands that actively erase deleted data blocks. Recovery from SSDs is possible but produces less complete results than recovery from traditional hard drives in many cases.
Encryption presents a fundamental limitation: encrypted data that cannot be decrypted is not useful even if it is recovered. Full-device encryption on modern smartphones and the BitLocker encryption used on many corporate laptops means that data recovery from these devices depends on access to the encryption keys as much as it depends on the recovery techniques applied to the storage media.
Forensic Best Practices
Act promptly: the earlier a device is secured for forensic examination, the more recoverable data is likely to remain. Every day that passes after a suspected incident is a day in which new data may overwrite the deleted content the investigation needs.
Do not power the device on: turning a device on after it has been identified as evidence can alter dozens of files and system artefacts. If a device needs to be transported, it should be transported in a powered-off state where possible.
Do not attempt recovery without specialist tools: standard recovery tools and data recovery services designed for accidental data loss use approaches that can overwrite the data they are trying to recover. Forensic recovery requires specialist software and specialist methodology.
Document everything: every step taken in relation to the device from the point of seizure should be documented, including who handled it, when, and what actions were taken. This documentation is the chain of custody record that establishes the integrity of the evidence.
Need to recover deleted digital evidence for an investigation or legal matter? Contact iSpy Detectives for expert forensic data recovery services.

