The Five eDiscovery Decisions that Determine Success

Jul 28, 2026 | Blog

Photo of Level Legal team members in a meeting room.

A Best Practices Guide for Making the Right Decisions at Every Stage of the EDRM — From Preservation to Production

 

For new attorneys, eDiscovery might look like a technical process that doesn’t impact case strategy — something you delegate and forget. This is a mistake. Most modern cases are won and lost in the discovery phase, long before trial, and the eDiscovery decisions you make will determine whether you end up with the win.

eDiscovery is a sequence of five decisions you own, each of which can advance your case strategically or derail it publicly. This article walks you through those five decisions and gives you the context and reasoning you need to operate credibly from day one. It is an excerpt from our publication, eDiscovery 101: A Field Guide for Associates. Download eDiscovery 101 for everything new attorneys need to know to set up an eDiscovery process for success, including checklists for each phase, example decision-making scenarios, how to identify issues to escalate, and much more.

A note on jurisdiction: The federal rules are the backbone of eDiscovery practice and the common vocabulary everyone uses, so this article is based on the federal rules. Be aware that state rules can and do diverge from the guidance in this document. For state court matters, be sure to refer to the rules of your jurisdiction.

Why eDiscovery Matters

Making the right decisions during the discovery process will arguably matter more to the success of your case than any other decisions you make. It is also where associates often bear much of the day-to-day responsibility. This includes running searches, drafting legal hold notices, coordinating collections, and communicating with opposing counsel about what has and has not been done. Those responsibilities carry real consequences. “I didn’t know” is not a defense. The courts have been clear for two decades that competence with ESI is a basic skill required to practice law.

The stakes are concrete. In DR Distributors v. 21 Century Smoking, counsel represented that production was complete without reasonably investigating the client’s systems; the result was roughly $2.5 million in sanctions and lasting credibility damage. In UANPF v. Carvana, a party agreed to produce hyperlinked documents without testing feasibility and was forced into a pilot that cost more than $200,000 and 1,170 hours for just two custodians (people who hold or control potentially relevant data). Neither of those was a technology failure. Both were decision failures — someone agreed to something, or skipped something, that a little discipline would have caught.

The Five eDiscovery Decisions that Determine Success

These decisions are the spine of the eDiscovery process. Strip away the vocabulary and the tooling, and eDiscovery is five decisions. In this article, we approach them in three ways: a question you must be able to answer “yes” to, a short list of what can go wrong, and case studies showing the cost of when things go wrong.

  • Decision 1: Identification and Preservation 
    • The Question: Do we know where the evidence lives, and have we ensured it won’t be lost?
  • Decision 2: Collection
    • The Question: Is this collection complete, defensible, and metadata-intact?
  • Decision 3: Meet and Confer/ESI Protocol
    • The Question: Are we agreeing only to things we can execute?
  • Decision 4: Review and Analysis 
    • The Question: Is our workflow reasonable, consistent, and validated?
  • Decision 5: Production
    • The Question: Is what we produced complete, accurate, and defensible?

Decision 1: Identification and Preservation

The question: Do we know where the evidence lives, and have we ensured it won’t be lost?

Identification is the process of determining who the key players (custodians) are and where potentially relevant data resides. Preservation is protecting that data from alteration or destruction the moment litigation is reasonably anticipated. These run together because you can’t preserve what you haven’t identified.

The duty to preserve is triggered by reasonable anticipation of litigation — which can be well before a complaint is filed. Federal rules are silent on how to preserve data; the obligation comes from common law. The practical mechanism is the legal hold: a written directive telling custodians to preserve relevant material and suspend auto-deletion. Issuing the notice is the beginning, not the end. You must monitor compliance.

Where It Goes Wrong

  • Preserving too late
  • Issuing a hold and never following up
  • Forgetting departing employees and decommissioned systems
  • Missing modern sources like Teams, Slack, texts, Generative AI (GenAI) chat logs, and ephemeral messaging apps
  • Relying on the client’s honor system instead of verifying

Case Study — The Classic and the Modern

In Zubulake v. UBS Warburg, counsel issued a hold but failed to supervise compliance; backup tapes were overwritten, and the court gave an adverse-inference instruction. Twenty years later, the same lesson recurs: In In re Google Play Store Antitrust Litigation, Google left a 24-hour auto-delete function active on internal chats and let employees decide for themselves what to preserve. The court held that a litigant cannot rely on an unmonitored honor system, leading to severe sanctions and millions in fees. You don’t merely issue a hold; you make sure it works.

Decision 2: Collection

The question: Is this collection complete, defensible, and metadata-intact?

Collection is the acquisition of the ESI you identified. The central tension is proportionality versus completeness. You have three basic methods, trading speed and cost against risk:

  • Full forensic collection — a forensically sound acquisition that preserves not only the user-created data but also system artifacts, metadata, and other evidence that may become relevant later. Often the lowest-risk approach is essential when authenticity, deletion activity, user behavior, timeline reconstruction, or other forensic questions are at issue. It is not always the most expensive or time-consuming option; the cost and complexity depend heavily on the data source.
  • Targeted collection — selected ESI from specific custodians, locations, date ranges, or repositories, collected in a defensible manner with appropriate validation and chain-of-custody documentation. The workhorse method for most matters because it balances proportionality, efficiency, and defensibility.
  • Self-collection — the custodian or client collects and provides their own data. Typically, the least expensive option, but also the one with the greatest risk of omission, alteration, over-collection, or spoliation. Rarely appropriate without clear instructions, lawyer oversight, and independent validation of what was collected.

Where It Goes Wrong

  • Collection methods that strip or alter metadata (which can itself be spoliation)
  • Letting an inexperienced client self-collect and treating counsel as a passive conduit
  • Failing to document the chain of custody so you can’t later prove what you did

The Four T’s Test

Before you let clients collect their own data, run the Four T’s test. If the answer to any of these questions is “no,” get help:

  1. Time — Does the client’s IT team have time to do this properly?
  2. Technology — Does the client have the right tools to collect defensibly?
  3. Training — Does the client know how to use those tools and document the process?
  4. Testimony — Would you and the client be comfortable testifying to the defensibility of this collection?

Case Study

In EEOC v. Formel D, the client self-collected and counsel acted as a passive conduit. The court held that counsel must test and validate the accuracy of a collection. This resulted in spoliation motions granted in part against counsel. Trust your client but verify the data.

Decision 3: Meet and Confer/ESI Protocol

The question: Are we agreeing only to things we can execute with certainty?

The Rule 26(f) meet and confer is the strategic leverage point of the whole case. It is where the parties define discovery scope, search methodology, and production format, ideally memorialized in an ESI protocol. Rule 26(b)(1) sets the governing standard: discovery must be relevant and proportional to the needs of the case.

The Sedona Principles, an industry-standard best practices guide published by the Sedona Conference®, capture the two ideas you’ll hear most: cooperation is expected (Principle 1), and the responding party is generally best situated to decide how to meet its own discovery obligations (Principle 6).

What Actually Matters in the Protocol

  • Scope (custodians, sources, date ranges)
  • Search approach (keywords, technology-assisted review (TAR), GenAI, and how you’ll validate)
  • Production format (native vs. image, required metadata, structured data)
  • Privilege protection
  • Feasibility (can your client comply with what you’re about to sign?)

Where It Goes Wrong

  • Agreeing to something to seem cooperative, then discovering you can’t do it
  • Overpromising on format
  • Skipping the 502(d) order that would have protected you

Case Studies

Two cautionary tales discussed above belong here. In DR Distributors, counsel represented completeness without reasonable inquiry and drew roughly $2.5 million in sanctions — if you can’t execute it, don’t agree to it. In Carvana, agreeing to produce hyperlinked documents before testing feasibility forced a $200,000-plus, 1,170-hour pilot for two custodians. Test feasibility before you sign the protocol.

Privilege at Scale: What a Rule 502(d) Order Does for You

When you produce hundreds of thousands of documents, some privileged material will occasionally slip through no matter how careful the review. Absent protection, producing a privileged document can waive privilege — potentially over the whole subject matter. Federal Rule of Evidence 502(d) is the fix: it allows the court to enter an order stating that production of privileged material does not waive privilege in that case or any other federal or state proceeding. A 502(d) order is cheap insurance, and forgetting to ask for one is a preventable, career-denting mistake. Ask for it in every case where you’re producing volume.

Decision 4: Review

The question: Is our workflow reasonable, consistent, and validated?

Review is where the legal team spends most of its time and money — commonly cited at 60–70% of total eDiscovery cost — because it is the most human-intensive stage. Review does two things: It identifies documents that are responsive (relevant and must be produced), and it identifies documents that are privileged (and must be withheld or redacted). Along the way, reviewers often code documents by issue to build the case narrative.

Three Tools, One Judgment that Stays Yours

You’ll hear three approaches to getting through the documents. The one-line version to remember: TAR ranks documents, GenAI explains them, and neither replaces attorney judgment.

  • Human review — attorneys reading documents. This is the baseline, still where the hardest calls land.
  • Technology-Assisted Review (TAR/predictive coding) — the software learns from reviewer decisions on sample sets and then ranks the remaining documents by likely relevance. TAR 1.0 builds a static model from expert-coded seed sets; TAR 2.0, or Continuous Active Learning (CAL), keeps learning from every reviewer decision. You don’t need to memorize the distinction — you need to know it prioritizes and ranks.
  • GenAI (large language models) — newer tools that can summarize, spot issues, and suggest relevance or privilege calls in natural language. These tools are powerful, but they predict language patterns, not legal truth, so their output is a starting point you validate, not an answer you adopt.

What Makes a Review Hold Up

Defensibility and effectiveness come from the same disciplines: clear definitions of relevance, privilege, and issues; consistent coding across reviewers; sampling and quality control (QC); a path to escalate hard calls; experienced oversight; and alignment between what you’re coding and what you must ultimately produce.

The Standard Doesn’t Change — Only How You Meet It

Rule 26(g) requires counsel to certify that a discovery response is complete and correct after a reasonable inquiry. That same standard applies whether you used human review, TAR 1.0 or 2.0, or a GenAI workflow. Every method must be validated through QC and sampling (for TAR and GenAI, that means measuring recall — did we find what we should have — and precision — how much of what we flagged was relevant). Courts evaluate every approach on the same three axes: reasonableness, proportionality, and defensibility.

Delegating Judgment Raises Risk

A useful way to think about technology risk is that the closer the tool gets to making the legal decision, the higher your exposure. Using TAR to prioritize documents or GenAI to summarize and suggest decisions are assistive, lower-risk uses. Letting TAR auto-code for privilege, or letting a GenAI make the final privilege call with no human validation, are decisive, higher-risk uses. Keep the human judgment attached to the decisions that carry legal consequences.

Decision 5: Production

The question: Is what we produced complete, accurate, and defensible?

Production is where mistakes become visible to the other side and the court. You deliver the responsive, non-privileged documents in the agreed format, with the agreed metadata. Quality control is non-negotiable and occurs both before and after the production. You must validate relevance calls, privilege calls, redactions, formatting, and data integrity. Confirm the redactions are “burned in.” A redaction that only hides text on screen but leaves it in the underlying file is a classic, catastrophic error.

Where It Goes Wrong

  • Producing in the wrong format
  • Broken or incomplete metadata
  • Redactions that didn’t take
  • Privileged documents slipping through (see the 502(d) discussion above)
  • Inconsistent family handling, where an attachment gets produced but its parent email doesn’t

Download the Full Guide

eDiscovery decisions shape case strategy, cost, and credibility long before production begins. Level Legal’s eDiscovery 101: A Field Guide for Associates provides a practical framework for the five eDiscovery decisions that determine success, including phase-by-phase checklists, example scenarios, a snapshot of ethical concerns, and a plain-English glossary of eDiscovery terms. Download it today to build the judgment and escalation instincts needed to supervise discovery with confidence, avoid preventable mistakes, and defend the process when the stakes are high.

Download eDiscovery 101: A Field Guide for Associates

Close Modal

Our Framework

Understand.

During this phase, we work to step away from any assumptions and guesses about what our customers needs, and let our research findings inform our decision-making. We learn more about our customers, their problems, wants, and needs, and the environment or context in which they will use the solution we offer.

Our Framework

Define.

During the Define phase, we analyze our research findings from the Understand phase and determine what is the most important problem to solve — and why. This step defines the goal. Then we can give a clear problem statement, describing what our customers’ needs are that we are trying to solve, making sure that we heard and defined their problem correctly.

Our Framework

Solve.

This phase is an important part of the discipline in our process. People often settle for the first solution, but the most obvious solution is often not the right one. During the Solve phase, we brainstorm collaboratively with multiple stakeholders to generate many unique solutions. We then analyze our potential solutions and make choices about which are the best to pursue based on learnings in the Understand phase.

Our Framework

Build & Test.

This phase is critical in developing the right solution to our customers’ problem. An organized approach to testing can help avoid rework and create exceptional outcomes. Starting small and testing the solution, we iterate quickly, before deploying solutions across the entire project.

Our Framework

Act.

During this phase, the hard work of prior phases comes to life in our customers’ best solution. The research, collaboration, and testing performed prior to project kick-off ensure optimal results.

Our Framework

Feedback.

At the project completion, we convene all stakeholders to discuss what went well, what could have been better, and how we might improve going forward. We call these meetings “Retrospectives,” and we perform them internally as a project team, and with our external customers. The Retrospective is one of the most powerful, meaningful tools in our framework.

Next