How to Determine Whether a Phone Was Actually Being Actively Used at the Time of an Incident

Cell Phone Call Detail Records (CDRs) can be powerful evidence. It can establish that a call connected, a text message was sent or received, a device exchanged data with a network, or a phone was associated with a particular cell site. But one of the most important lessons in CDR analysis is also one of the easiest to overlook: activity connected to a phone does not always prove that a person was actively using it.

 

That distinction matters in personal injury litigation, commercial vehicle crash cases, and criminal defense. A plaintiff may argue that a driver was distracted by a phone moments before impact. A defense attorney may need to show that a carrier event does not establish manual use, screen activity, or even the identity of the person holding the device. In a criminal case, the government may point to a call, text, location event, or app related record as evidence of conduct, while the defense may need to challenge what that evidence can actually establish.

 The right answer is usually not found in one record alone.

 In our LinkedIn poll, we asked:

 Which evidence best evaluates actual phone use?

 The choices were:

 

·         CDR calls and texts

·         Data session records

·         Device forensic artifacts

·         Combined timeline analysis

 

Every answer can be valuable. The strength of each depends on the question being asked, the quality of the records, and whether the evidence is being interpreted in context.

Smartphone showing call detail records and text message metadata connected to generic cell towers, with a commercial truck and courthouse in the background.

1. CDR Calls and Texts

Call Detail Records, commonly called CDRs, are often the first records attorneys seek. They can identify incoming and outgoing calls, associated phone numbers, start and end times, duration, and sometimes the cell site locations used during the event. Carrier produced text message records may also identify the date, time, and telephone number associated with an SMS message.

 For a distracted driving claim, this information can be highly relevant. If a driver placed a call that began shortly before the first 911 call and ended after the first 911 call, evidence supporting an argument that the driver was occupied with a phone exists. If a text message was sent seconds before a crash, it can be an important fact in the overall case timeline.

 In criminal defense, the same records may be used to establish or challenge an alibi, assess whether a witness account fits the digital timeline, or test an allegation that a defendant communicated with another person at a particular time.

 Still, CDRs have limits.

 A call record may show that a phone call occurred, but it generally does not establish who was speaking. The subscriber may not have been the person using the phone. A passenger may have used the device. The phone may have been connected through hands free technology, though that can be considered a distraction as well. A call may also have been answered, placed, or continued without meaningful interaction by the user at the critical moment.

 Text message metadata presents similar issues. A record indicating that a message was sent may be very important, but it does not necessarily reveal whether the message was manually typed at that exact time, whether it was sent by the account holder, or whether the device was in the driver’s hands.

 For plaintiff attorneys, call and text records can provide a strong starting point. For defense attorneys, the key is to avoid allowing a timestamp to become a conclusion that the records cannot independently support. In criminal defense, counsel should also examine whether the records prove actual use, merely establish an account event, or leave room for other reasonable explanations.

 CDRs are useful evidence. They are not always the complete answer.

Smartphone connected to a cell tower with digital data streams and background app activity icons.

2. Data Session Records

Data session records can provide another layer of information. Smartphones routinely connect to carrier networks for web browsing, applications, email, cloud syncing, mapping, messaging, software updates, and other background functions. Depending on the carrier records available, data sessions may show dates, times, duration, approximate data volume, cell site information, and other network details.

 In a crash case, an attorney may see data activity close in time to impact and reasonably ask whether the driver was using a social media platform, navigation application, video service, or messaging application. In a criminal case, data activity may be relevant to a location timeline, alleged online conduct, or a claim that someone accessed a particular service.

 But data session records require careful interpretation.

 Not every data event reflects active human use. A phone may exchange data because an application refreshed in the background. It may be checking for email, uploading photographs automatically, syncing files to cloud storage, receiving push notifications, updating a location service, or communicating with an application without the user touching the device.

 That does not mean data session records lack value. It means they need context.

 For example, a large, sustained data session that aligns with a device artifact showing an application was open may support an inference of active use. A brief isolated data event, without other supporting information, may have many possible explanations, such as a text message. The timing, duration, frequency, and relationship to other evidence are all important. Data usage by itself cannot prove active use by the user, but it can give added weight to the demand to examine the phone itself.

 Plaintiff counsel may use data session evidence to identify areas requiring further investigation. Defense counsel may use it to explain why a data connection does not automatically prove distraction. Criminal defense attorneys may use the same analysis to challenge a claim that network activity proves a person intentionally used a device at a specific time.

 The most responsible approach is to treat data sessions as clues, not automatic conclusions.

Forensic examiner reviewing a smartphone and laptop displaying an evidence timeline, app activity, and location data.

3. Device Forensic Artifacts

Carrier records describe activity observed by the network. A forensic examination of the phone itself may provide a closer look at what happened on the device.

 Depending on the device, operating system, condition of the phone, available backups, and scope of a lawful examination, forensic artifacts may help identify application use, screen activity, notifications, messages, photographs, web history, location data, Bluetooth connections, deleted information, and other relevant events.

 This evidence can be particularly important when the real question is not whether the phone communicated with a network, but whether someone was actively interacting with it.

 In a commercial vehicle crash case, a device examination may reveal that a messaging application was open near the time of a collision. It may show a drafted or sent message, an active navigation application, a photograph created near the crash time, or a sequence of activity that helps explain a carrier record.

 In criminal defense, device evidence can be equally significant. It may support a timeline that contradicts an allegation. It may show that another person had access to the phone. It may reveal that a relevant application was not used when the prosecution claims it was. It may also show that a device was locked, inactive, or otherwise inconsistent with an assumption of active use.

 Forensic artifacts also have limits. A phone may be damaged in a crash. It may have been replaced, reset, repaired, or improperly preserved. Relevant data may be overwritten or deleted. Some information may exist only in backups or cloud accounts. Other artifacts may require careful interpretation by someone who understands how a particular device or application records events.

 Attorneys should also be cautious about assuming that a missing artifact proves something was deleted intentionally. It may be relevant, particularly when carrier records show communications that are not present on the phone, but the explanation should be evaluated carefully. Preservation history, device handling, user behavior, and technical factors all matter. PROPER PRESERVATION IS CRITICAL!

 Device evidence can be among the most revealing forms of digital evidence, but only when collected, preserved, and analyzed appropriately.

Digital timeline combining cell phone call records, data activity, vehicle telematics, dash camera footage, GPS information, and courtroom evidence.

4. Combined Timeline Analysis

Combined timeline analysis is often the strongest answer because it brings the different sources together.

 A single CDR may show a call. A data session may show network activity. A phone examination may show application evidence. None of those records should automatically be viewed in isolation. The more reliable approach is to compare them with other available evidence and determine whether the full timeline makes sense.

 In personal injury and commercial vehicle crash litigation, that may include:

 

·         Call Detail Records and data sessions

·         Device forensic artifacts

·         Event Data Recorder information

·         Electronic Logging Device records

·         Vehicle telematics

·         Dash camera or in cab video

·         Surveillance video

·         Dispatch communications

·         Witness statements

·         Police reports

·         Crash reconstruction evidence

·         GPS and navigation records

For example, a CDR might show an outgoing call two minutes before a crash. Vehicle data may show the truck began drifting from its lane shortly afterward. A device examination may show no evidence that a messaging application was open. Witness testimony may indicate the driver was using a hands free system. Together, those facts can support a more accurate and nuanced analysis than any single record could provide.

 The same approach is valuable in criminal defense. A carrier record may place a phone in the general area of an alleged event, but location evidence should be compared with other records, including video, vehicle data, digital account activity, witness accounts, and the limits of cell site analysis itself. A phone associated with a location is not always the same as proving the phone’s user was there, and proving the user was there is not always the same as proving the alleged conduct occurred.

 Combined analysis also helps identify inconsistencies. If a witness claims they were asleep, a comparison of calls, device activity, app records, location events, and video may either support or challenge that statement. If a driver claims a phone was not in use, the timeline may reveal evidence that deserves closer examination. If an opposing expert reaches a broad conclusion from one isolated carrier event, a combined analysis can identify whether the conclusion is supported by the full record.

 The goal is not to make digital evidence say more than it can prove. The goal is to develop the most reliable explanation of what happened.

Attorney reviewing a phone preservation checklist, subpoena document, smartphone, and digital evidence timeline on a laptop.

Tips for Attorneys

Preserve the phone quickly. A damaged, replaced, reset, or routinely used phone may lose valuable evidence over time.

Request carrier records early. Retention periods vary, and important records may be unavailable if preservation and subpoena efforts are delayed.

Specify the time zone. Carrier records may be produced in a time zone different from the one used in police reports, vehicle data, witness accounts, or other evidence.

Do not treat a data session as proof of active use. Determine whether the activity could have resulted from a background process before drawing conclusions.

Compare records with other independent evidence. Carrier records should be evaluated alongside vehicle data, video, location evidence, and witness testimony.

Ask what the evidence actually proves. A call, text, or data event may be significant, but the record may not establish who used the phone, how it was used, or whether it caused the relevant conduct.

 

Involve a qualified forensic examiner early. Early consultation can help attorneys identify what should be preserved, what records to request, and how to avoid overlooking critical context. Digital evidence id fragile and time is of the essence.

Courthouse and scales of justice connected by digital evidence lines to a smartphone displaying CDR data, vehicle timeline, and forensic evidence file.

Conclusion

Determining whether a phone was actually used at the time of a crash or alleged offense requires more than finding a single call, text, or data event. CDRs can reveal important communications. Data session records can identify network activity. Device forensic artifacts can provide valuable detail about what occurred on the phone itself.

 But the most reliable conclusions usually come from combined timeline analysis.

 For personal injury attorneys, this approach can help establish or challenge distracted driving claims and place phone activity in the context of a collision. For commercial vehicle cases, it can be compared with telematics, ELD records, and video evidence. For criminal defense attorneys, it can expose assumptions, test the reliability of the government’s timeline, and distinguish evidence of device activity from proof of intentional human conduct.

 Cell phone evidence can be compelling. It should also be handled carefully. The strongest analysis does not simply ask whether a phone produced a record. It asks what the record means, what it does not mean, and whether the complete timeline supports the conclusion being offered.