The evidentiary question has several parts. It may be necessary to establish the system architecture, the security measures, the person’s permissions, the access event and the use that followed. Only the relationship between these elements shows whether the statutory requirements may be met.
Technical reconstruction may involve authentication records, timestamps, access logs, configuration states, permission lists and indications of the devices used. Their value depends on how the data was generated, stored and evaluated. A timestamp or IP address does not, without further assessment, identify a particular person.
The authorisation history is also important. A former access right, an administrative assignment, a test environment or shared use can change the central question. The relevant point remains the specific authority at the time of access and the purpose of the conduct.