An ESI protocol is the agreement — usually entered as a court order — setting out how electronically stored information will be preserved, collected, searched, and produced in a case. It fixes formats, metadata fields, search methodology and privilege handling before production, rather than litigating each afterwards.
What it is for
Almost every expensive eDiscovery dispute is a disagreement that could have been settled cheaply at the outset and was instead discovered after someone had spent money. Production arrives as images when the requesting party needed native files. Metadata fields the other side considers essential were never captured. Search terms return two million documents and nobody agreed in advance what happens next.
An ESI protocol front-loads those decisions to the point where they cost an hour of negotiation instead of a motion, a re-production and a schedule extension.
What it should actually cover
Scope. Custodians, date ranges, and systems — including which sources both sides agree are not reasonably accessible, so that question is closed rather than lurking.
Form of production. Native, near-native or image, and specifically for the formats where it matters most: spreadsheets, presentations, databases, and messaging.
Metadata fields. An enumerated list. "Standard metadata" means different things to different vendors, and the disagreement surfaces only once a production is loaded and something is missing.
Search methodology. Whether search terms, technology-assisted review, or both. If terms, how they are negotiated, tested and revised — and, importantly, whether hit counts are shared before terms are finalised.
De-duplication and threading. Whether duplicates are removed globally or per custodian. This materially changes what a custodian appears to have possessed, and it is worth being explicit about.
Privilege. Log format, categorical logging where appropriate, and a clawback provision. Under Federal Rule of Evidence 502(d) a court order can preserve privilege over inadvertently produced material far more robustly than a bare agreement between the parties, and there is no good reason to leave that on the table.
Modern data types. Chat and collaboration platforms, ephemeral messaging, mobile data, and how threads are unitised for production. Protocols drafted from a 2010 template are silent on the sources where most disputes now live.
Where they go wrong
The most common failure is a protocol copied from another matter and signed by lawyers on both sides without anyone technical reading it. Provisions that are impossible to execute in the parties' actual systems get agreed, and the impossibility surfaces at production. Having the people who will run the collection review the draft costs very little and prevents most of this.
The second failure is a protocol with no mechanism for changing it. Facts develop, custodians surface and volumes turn out differently than estimated. A protocol that cannot be amended without a motion becomes an obstacle rather than a framework.
When a neutral helps
Where the parties are sophisticated and hostile, or the data environment is genuinely complex, a technical special master or eDiscovery neutral can resolve protocol disputes in days rather than through motion practice. Courts increasingly appoint one at the protocol stage rather than waiting for the disputes to arrive.
From our work
Dealing with esi protocol in a live matter?
Our examiners and testifying experts work these questions for a living. Tell us what you're facing.
Reviewed by Law & Forensics. See our editorial standards.
