Skip to content

Compare

Preservation vs. collection

Preservation stops relevant data from being destroyed. Collection gathers it for processing and review. They are separate obligations with separate timing: preservation is urgent, comparatively cheap and legally mandatory once the duty attaches, while collection can usually wait until scope is settled.

Preservation compared with Collection across 6 dimensions
DimensionPreservationStop deletion. Leave the data where it lives.CollectionGather the data for processing and review.
What triggers itThe duty attaches when litigation is reasonably anticipated — often before filing.A discovery request, an investigative need, or an agreed protocol.
UrgencyImmediate. Retention policies and device refresh cycles run regardless.Can follow once custodians and scope are settled.
CostLow — mostly administrative: suspend deletion, notify custodians.Substantial, and it drives processing, hosting and review cost downstream.
Consequence of getting it wrongSpoliation. Under Rule 37(e), potentially case-dispositive.An incomplete production — remediable by collecting again.
Who does itInternal IT and system administrators; nobody else can change retention settings.A forensic examiner or eDiscovery vendor, depending on the source and the stakes.
Scope postureBroad. Over-preserving costs storage.Narrow and proportional. Over-collecting costs review.

Choose Preservation when

Preserve first, always, and preserve broadly. The duty attaches on reasonable anticipation of litigation, not on filing, and the cost of holding data is storage. Suspend auto-deletion on mail, chat and collaboration platforms; pause backup rotation; and connect the hold list to the HR offboarding process so a departing custodian's device is not wiped by routine IT hygiene.

Choose Collection when

Collect once the custodian list, date range and sources are settled — ideally after an ESI protocol has fixed formats and metadata fields, so nothing has to be redone. The exception is any device at risk of being lost, wiped or reissued: those get imaged immediately, because preservation of a physical device you do not control is not achievable by policy.

Where this goes wrong

The two are conflated in opposite and equally costly directions. Treating collection as preservation means nothing is actually preserved until collection happens — so the three weeks spent negotiating scope are three weeks in which auto-deletion keeps running and the SSD in a returned laptop keeps erasing itself. Treating preservation as collection means gathering everything from everyone immediately, which converts an administrative task into a seven-figure review population before anyone has established what the case is about.

Preserve in place, wherever possible

The default should be leaving data where it lives and stopping it from being deleted. Suspending a retention policy is an administrative action; collecting the same data is a project.

This works well for systems the organisation controls — mail platforms, collaboration tools and cloud storage generally have native hold or retention-lock features designed for exactly this. It works poorly, or not at all, for three categories, and those are where immediate collection is the only real preservation:

  • Devices leaving custody. A departing employee's laptop cannot be preserved in place if it is about to be wiped and reissued.
  • Solid-state storage. The drive erases deleted content on its own schedule whenever it has power, so a policy instruction does not stop the loss.
  • Platforms with no administrative control. Consumer messaging apps on personal devices, where the only preservation option is capturing the device.

The instruction that is not enough

Sending a legal hold notice telling custodians to preserve their messages does very little on a platform configured to delete automatically. The custodian cannot see the setting and cannot change it. Someone with administrative access has to suspend it, per system.

This is the single most common preservation failure we encounter, and it is invisible from inside: the notice went out, the custodians confirmed, and the data deleted itself anyway.

Why the sequence saves money

Preserving broadly and collecting narrowly is not a compromise between two goods — it is how both obligations are met at the lowest total cost.

Broad preservation is cheap and satisfies the legal duty, whose failure mode is severe and sometimes uncurable. Narrow, proportional collection controls the expensive part, whose failure mode is that you collect again. Reversing them — narrow preservation, broad collection — inverts both risks: it exposes the organisation to spoliation while spending heavily on review.

Documenting it

What is defended later is the process rather than the outcome. A short contemporaneous record of when the duty was assessed to attach and why, which systems were placed on hold and by whom, and how the custodian list was built, converts a challenge into a discussion. Reconstructing that record two years afterwards, from memory, does not.

From our work

Which one does your matter need?

Our examiners and testifying experts work these questions for a living. Tell us what you're facing.

Reviewed by Law & Forensics. See our editorial standards.