Spoliation is the destruction, alteration or failure to preserve evidence that a party knew or should have known was relevant to litigation. It does not require bad intent — routine auto-deletion running after the duty to preserve attaches is the most common form, and the most commonly sanctioned.
The two questions a court asks
Spoliation analysis almost always resolves into two findings, in order. When did the duty to preserve attach? and what happened to the evidence after that moment?
The duty attaches when litigation is reasonably anticipated — which is usually earlier than parties assume, and frequently before a complaint is filed. A demand letter, an internal investigation, or a regulator's inquiry can each start the clock. The date matters enormously, because everything before it is ordinary business and everything after it is potentially sanctionable.
Why this is mostly an accident
The caricature of spoliation is a defendant shredding documents. The reality is a mail server with a 90-day retention policy that nobody paused, a messaging platform set to auto-delete, a laptop reissued through standard offboarding, or a backup rotation that overwrote the relevant tape three weeks after the demand letter arrived.
Every one of those is a system doing exactly what it was configured to do. That is precisely the problem: the duty to preserve is affirmative, so "we didn't do anything" is not a defence when the not-doing was the failure.
The federal standard for electronic evidence
For electronically stored information, Rule 37(e) narrowed what had been a wide and inconsistent body of case law. The rule applies where ESI that should have been preserved is lost because a party failed to take reasonable steps, and it cannot be restored or replaced through additional discovery.
From there it splits. Where the loss causes prejudice, a court may order measures no greater than necessary to cure it. Where the party acted with intent to deprive another of the information, a court may go considerably further — an adverse-inference instruction, or dismissal.
That distinction is the whole ballgame in practice. Negligent loss is a problem to be remedied; intentional loss can decide the case. Much of the litigation under this rule is about which side of that line the conduct falls on, and intent is usually proved circumstantially from forensic artifacts rather than admitted.
What the forensic record shows
Deletion rarely happens invisibly. Wiping tools leave installation traces even after the wiped data is gone. Mass deletions produce a distinctive timestamp pattern. File system journals, event logs, and cloud audit trails often record activity the deleted content itself no longer proves.
This cuts both ways, and it is worth saying plainly to clients on both sides. The same artifacts that establish intentional destruction can also demonstrate that a loss was routine and automated — which converts a potentially case-ending finding into a curable one.
Ephemeral messaging is the current fault line
Disappearing-message features are a live and unsettled area. Courts have treated the deliberate use of ephemeral channels for business communications, after a preservation duty attached, as evidence of intent rather than as a neutral technology choice. Organisations that permit these tools without a policy governing their use in litigation are accumulating an exposure that surfaces years later, at the worst possible moment.
From our work
Dealing with spoliation in a live matter?
Our examiners and testifying experts work these questions for a living. Tell us what you're facing.
Reviewed by Law & Forensics. See our editorial standards.
