Fisheries VMS Domain · Lesson 12 of ∞ · Second pass · ← Lesson 11
Second pass · Surveillance, made prosecutable
A detected violation that can't survive a defence lawyer's questions about how it was captured isn't a violation — it's an unusable data point. This is the discipline that connects.
Everything covered so far — geofence intersections, event capture, violation detection — describes how e-Boat notices something. ToR group C-066..C-076 ("Documents, notifications") governs what happens next: turning a detection into something that can actually be acted on, up to and including a prosecution or licence sanction. That's a different discipline from detection, and it has its own rules, borrowed from digital forensics generally.
Chain of custody is the documented, unbroken record of who handled a piece of evidence, when, and what (if anything) was done to it, from the moment it was captured to the moment it's presented. The core reasoning: evidence is only as trustworthy as the record of what happened to it — if a violation record could plausibly have been altered between detection and presentation, with no way to prove otherwise, the record's evidentiary value collapses regardless of whether it was actually altered.
Sources: American Military University — Maintaining Chain of Custody for Digital Forensic Evidence, Eclipse Forensics — Chain of Custody in Digital Forensics.
A dedicated Evidence Collection Manual for Fisheries Enforcement, published to support Port State Measures Agreement implementation, exists specifically because generic chain-of-custody practice doesn't automatically cover fisheries evidence types (position tracks, catch photos, inspection forms). Its central point, in short: correct chain-of-custody procedure has to be followed or the case is weakened — this isn't a nice-to-have on top of detection, it's a precondition for detection to matter legally.
Translated into system requirements, chain of custody generally demands:
The tender's own assumptions register grounds this in specific numbers rather than leaving it abstract: scanned document attachments (inspection photos, signed forms) are capped at 5MB, run through antivirus scanning (ClamAV) on upload, and held for a 7-year retention period specifically for evidentiary attachments — a duration set by the evidentiary need, not by ordinary application-log retention norms. That retention number is itself a tell: 7 years is far longer than any operational reason (debugging, analytics) would justify, and matches typical statute-of-limitations and appeal-window horizons for administrative/legal proceedings instead.
Something unclear, or want to go deeper on any term here? Ask the agent that built this lesson — it's your teacher for this workspace, not just a lesson generator.