IT security intelligence. Since 2006.Cloudflare services ↗
TRUST-IT / Practical guide

eDiscovery collection: what makes a delivery reviewable?

A folder of exported files is not a complete evidence delivery. Define scope, preserve context and verify the collection before legal or investigative review begins.

Storage media and document boxes prepared for evidence processing.
About 4 min read

Turn the matter into a collection specification

Begin with the questions the review must support, the relevant period and the people or business functions likely to hold material. Identify mailboxes, collaboration spaces, shared drives, devices and external systems. Record account aliases, ownership changes and departed employees. A list of personal mailboxes alone may miss a transaction negotiated in a shared channel or approved through a workflow application.

Agree the authority, privacy constraints, access permissions and handling requirements with the responsible legal and organisational stakeholders. Separate the technical collection specification from legal decisions about relevance, privilege and disclosure. Set a change process: new custodians, sources or time periods should be approved and recorded, so the final delivery can be reconciled with the instructions.

Distinguish preservation from collection

Preservation aims to protect relevant information against loss or alteration; collection creates material for examination. They require separate checks. In a hosted platform, verify which locations a hold covers, whether it is active and what exclusions remain. A search export does not demonstrate that the original source will remain available next month, and a preservation setting does not establish that every required item has been collected.

Record the platform, account identifiers, collection method, query, time zone, operator and execution period. Capture warnings, failed locations and available process reports. For dynamic sources, explain how edits, deleted items, versions and linked attachments are represented. Platform capabilities, permissions and licensing can affect the result, so validate the actual tenant rather than assuming documentation describes its configuration.

Test whether the search finds what matters

Use known relevant items to challenge the search design. Include aliases, language variants, date boundaries and representative attachment types. Ask what the query cannot evaluate: encrypted files, unsupported formats, unindexed items, images without usable text or content outside the selected sources. A zero-result search is meaningful only within those limits.

Separate discovery searches used to understand the data from the approved collection query. Retain query versions and the reason for revisions. Sample both included and excluded material where authorised, with selection rules that can be explained. If machine-assisted review prioritises documents, preserve the review method and human decisions; a model score should not silently determine legal relevance or privilege.

A sealed storage device, delivery records and evidence packaging.
The delivery package should connect each reviewed item to its source and handling record.

Preserve relationships and processing history

Keep sufficient context to reconnect a message with its attachments, a document with its versions and an exported item with its source. Deduplication may reduce review effort, but it must not erase the record that the same document occurred in different custodians’ collections. Document the deduplication unit, the metadata retained and the method for recovering those relationships.

Store originals separately from normalised text, rendered documents and working copies. Record processing tools, versions, settings and errors. Cryptographic hashes can support verification that particular delivered bytes match an earlier copy; they do not establish authorship, truthfulness or completeness of the collection. Preserve a clear path from a reviewed document back to the acquired item and its collection record.

Reconcile the delivery before handing it over

Agree a reconciliation model that follows the platform’s counting rules. Search hits, exported messages, attachments, document versions and processed review records may be different units. Explain expected expansions and reductions rather than demanding that every stage has the same count. Investigate unexplained differences and separate empty, failed, excluded and successfully processed items.

Validate a sample of the actual delivered package. Confirm that native files open, text extraction is usable, attachments remain linked, metadata maps correctly and redactions behave as intended in every included representation. A redacted PDF may be undermined by an unredacted native file or text sidecar. Record the recipient, transfer channel, integrity check and acceptance outcome.

Specify useful deliverables and closure

Request the approved scope, source inventory, collection log, processing report, exception register, metadata specification and delivery manifest alongside the evidence. Define how questions and additional collections will be handled. At closure, agree retention, return or disposal with the authorised owner, accounting for any continuing preservation requirement; do not treat delivery as automatic permission to delete.

TRUST-IT can support technical scoping, collection validation, processing and evidence presentation in coordination with your advisers. For an initial discussion, describe the matter, sources, approximate volume and deadlines without sending sensitive evidence through the public contact form. A secure exchange method can be agreed once the handling requirements are understood.

Further reading

Put the guidance to work

Electronic evidence preservation, targeted collection, document processing, technical analysis and support for legal review.

eDiscovery & dispute support

What’s your next
technology challenge?

TRUST-IT / FIND YOUR NEXT STEP

How can we help?

Popular topics

Search the public TRUST-IT website.