Glossary term
Active Data
Active data is the data currently visible to the user through normal operating system access, as opposed to deleted files, slack space, unallocated space, or system-protected artifacts.
Active data is what shows up in a user's File Explorer, Photos app, mailbox, or browser when they sit down at the device. It is the easiest data to collect because it is indexed by the operating system. A regular backup captures active data only.
Forensic examination goes well beyond active data. Deleted file recovery, slack space analysis, unallocated cluster examination, and system-artifact parsing all surface evidence that is not visible to the user. In many matters the most important findings come from outside the active data set: deleted messages recovered from a SQLite write-ahead log, system event logs that record activity the user did not know was being logged, browser cache files that survive history clearing.
The distinction matters in litigation because production protocols sometimes contemplate "active data only" collection, which can miss critical evidence. Counsel needs to understand the trade-off before agreeing to a scope.
