Slashdot Mirror


Businesses Generally Ignoring E-Discovery Rules

eweekhickins writes "A full year after the institution of new federal e-discovery court rules, only a minority of companies are paying attention. Keeping track of every IM, email, and document for a court order that may never come must seem like a tall order. Researcher Michael Osterman said that only 47 percent of companies have some kind of e-mail retention policy in place. 'I don't think it's difficult to understand the rules,' Osterman told eWEEK. 'I just think that it sometimes takes headline shock to make people move on some things.'"

26 of 109 comments (clear)

  1. Apparently it doesnt hurt them enough by sethstorm · · Score: 2, Funny

    Time to raise the penalties for violations - and close off any foreign country escape route from this regulation.

    --
    Twitter supports and protects racists - by smearing their critics with the "Hate Speech" label.
    1. Re:Apparently it doesnt hurt them enough by plague3106 · · Score: 3, Insightful

      How about it's a stupid law and is being rightfully ignored? Ya, that's it. It places an undo burden on business, and really, they're being asked to keep evidence which may incriminate them. Might as well ask a rapist to keep detailed records too so they can be subpoenaed.

    2. Re:Apparently it doesnt hurt them enough by rootofevil · · Score: 2, Funny

      oh to have the burden of the undo! i should be so afflicted...

      undue burdens on the other hand, those are just not cool.

      --
      turn up the jukebox and tell me a lie
    3. Re:Apparently it doesnt hurt them enough by jo42 · · Score: 2, Funny

      GWB, is that you? And, just what did happen to all those Whitehouse emails..?

  2. Or Maybe by Atomm · · Score: 2, Interesting

    it is a bad law that failed to consider the impact it would have on business to actually implement the requirements.

  3. Is this ALL companies by doroshjt · · Score: 2, Interesting

    Is law for all companies or just Public corporations? Seems an excessive burden to put on small businesses?

  4. The law should be overturned by Bryansix · · Score: 3, Insightful

    The law is burdensome on businesses. Keeping track of email is one thing. Keeping all communication archived is ridiculous. We just came up with a solution to archiving email so we can finally delete some mailboxes off of our exchange boxes. My co-worker just wanted to purge the boxes and not back them up. I convinced him that even if this law didn't exist the mail may be useful for us in a court case so it would be worth keeping.

    Now we used to use Spector 360 which would satify this ridiculously overbroad law. The software is nuts though and opens all kinds of issues like keeping the data secure since it captures all keystrokes and so people may have CC#, SSN or bank account numbers in their database records kept by this program.
    When we moved we stopped using the program.

    1. Re:The law should be overturned by Zordak · · Score: 2, Informative

      This "law" should not be "overturned." It is not a "law." It is Rules of Civil Procedure for parties in litigation in Federal court. You can read them here. The rule you want is R. 34.

      This post does not constitute legal advice and is not endorsed by Jackson Walker LLP

      --

      Today's Sesame Street was brought to you by the number e.
  5. the FRCP by theMerovingian · · Score: 5, Informative


    The Federal Rules of Civil Procedure are being grossly mischaracterized here. The main purpose of the changes is to make it so companies can't intentionally obfuscate their data storage in order either 1) increase the timeline for digital discovery; or 2) increase the costs (especially to the non-business plaintiff) for digital discovery.

    The FRCP are not a set of regulations to govern businesses, it just means that parties with digital information will bear the burden to produce it in the event of a lawsuit. Depending on the frequency with which your company is sued, it may or may not be a good idea to make it faster to access your backups.

    You aren't under an obligation to save all electronic corresponce unless you are in a heavily regulated industry with special rules requiring that. However, anyone who deletes or destroys documents once a court order has been issued is in pretty big trouble if they get caught. This has been true long before the advent of email.

    IMPORTANT NOTE: I am not a lawyer, this is not legal advice, there is no formation of attorney client privilege, this does not serve as an offer to represent you, your family, or anyone you have ever met, consult the advice of a licensed attorney in your jurisdiction before taking any action, the forgoing is for informational and educational purposes only, and any and all warranties inherent in this post whether express or implied are hereby disclaimed.

    --
    "If you think you have things under control, you're not going fast enough." --Mario Andretti
    1. Re:the FRCP by Brian+See · · Score: 2, Informative

      I am a lawyer and my practice focuses on eDiscovery. In other words, I translate between lawyers and people who read /.

      Lots of interesting comments in this thread. There is a lot of FUD out there (like that's news). I hardly know where to start.

      First, sophisticated litigants have seen increased costs from eDiscovery compliance, because "Joe Average" lawyer on the other side is getting more sophisticated about these issues. The new eDiscovery rules require companies to make pretty specific disclosures regarding what electronically stored information they have that might contain potentially relevant information. Federal judges are also more sophisticated on these issues now, and are expecting more of people. It's becoming a lot more difficult to 'hide your head in the sand' and hope the other side doesn't ask about this stuff.

      Because the cost of searching, reviewing and producing email (and other electronic information) can be so burdensome, the table stakes for pursuing or defending a lawsuit can be higher than "before".

      theMerovingian said: The FRCP are not a set of regulations to govern businesses, it just means that parties with digital information will bear the burden to produce it in the event of a lawsuit.

      Not entirely true. In some cases, courts have held that cost-shifting is appropriate.

      theMerovingian said: Depending on the frequency with which your company is sued, it may or may not be a good idea to make it faster to access your backups.

      This is dangerous advice. There are companies out there which are making it cheaper to access backups. If you make it faster and easier to access information on offline (tape) or nearline storage, then you may reduce your ability to argue that the information is "not reasonably accessible due to undue cost or burden" under Rule 26(b)(2)(B). I have seen clients tripped up because IT people somehow get the notion that the lawyers WANT them to have really long retention periods on backups "just in case". While lawsuits sometimes require backup tapes to be held, if there isn't a lawsuit, it often isn't helpful to keep this data lying around when there isn't any business need for it.

      theMerovingian said: However, anyone who deletes or destroys documents once a court order has been issued is in pretty big trouble if they get caught.

      Agreed on the court order part -- don't violate court orders! But there's lots of room to argue before that order gets issued. When a company is sued, does that mean they have to create a bitstream image of each and every computer in the organization? (After all, just continuing to use the computer overwrites the pagefile and other unallocated space -- that's destroying potentially relevant data!) There are vendors (and even some lawyers) out there who are telling companies that they have to do this. The real answer is that in many cases, locking down every last bit of data is not necessary.

  6. Re:Privacy? by Bryansix · · Score: 2, Insightful

    Because people have a certain expectation of privacy in email communications even though they shouldn't if the email account is a work email account. Also workplaces ready chat is kind of sketchy. My work used to do it. Not anymore.

  7. More business for lawyers by wsanders · · Score: 4, Insightful

    You inconsiderate clod, it creates nothing but opportunity for lawyers to charge endless fees for e-discovery. Imagine the new volumes of information available for them to charge $500 an hour to sift through! And if they can charge $1.50 per page to make copies of documents, imagine how much they can markup deleted email recovery services! And the damage awards they can demand from corporation-hating juries for failure to retain data that may or may not have any relevance to the case at hand.

    The opportunities are endless!

    --
    Give a man a fish and you have fed him for today. Teach a man to fish, and he'll say "WHERE'S MY FISH, YOU IDIOT?"
    1. Re:More business for lawyers by Arguendo · · Score: 2, Informative
      Actually, speaking as one lawyer who has had to sift through way too much e-discovery, I can tell you uncategorically that, no, we do not like earning fees sifting through your emails to co-workers about about the latest website or your boss's new haircut.

      PLEASE, PLEASE, PLEASE create a regular document retention policy that mandates the deletion of all unnecessary emails and other e-documents on a regular basis. You CAN delete these files and you should. But if you wait until the lawsuit is filed, it's too late - and now we have to wade through all this crap. That's the point.

  8. You can tell companies aren't paying attention. by olddotter · · Score: 3, Insightful

    If they were, their lobbists would be be crawling all over this. The cost of capturing and storing all of the digital communications made by employees is non trivial. I know of one company just trying to give their lawyers access to query and retain e-mails. That project is a mess. I can't imagine trying to keep instant messaging along with, etc., etc. .....

  9. Ignore The Law: I AM the judicial branch by Anonymous Coward · · Score: 3, Funny


    'cause I do.

    Cheers,
    W

  10. This is my business by gurps_npc · · Score: 4, Informative
    I do e-discovery related document loading and exporting.

    I can tell you the following:

    1. It is a big business.

    2. It is not "pointless".

    3. The reason the laws were passed is that people were intentionally deleting documents or worse LYING and claiming they had deleted it when back ups were clearly present. They lied because of the expense it would take to recover the back-ups. Honestly, was it that hard to have the lawyers talk directly to the tech people, instead of too middleman that cared more about money than their legal responsibilities?

    4. The law at heart simply states that if you have documents then deleting it BECAUSE of a legal action is illegal.

    5. The law clearly allows you to routinely delete documents, say 1/year, or even every month.

    6. All it really takes to satisfy the law is a commitment to a reasonable data-retention policy. The only businesses that don't or can't comply are

    A. those that have been giving their IT department the short-shift, not providing a reasonable amount of cash for data and back-ups.

    B. Those that don't realize that after you are SUED or CHARGED with a crime means you have to spend money on the law-suit. That includes the responsibility of saving and organzing the data you collected.

    --
    excitingthingstodo.blogspot.com
  11. Too Expensive by pickapeppa · · Score: 2, Interesting

    This kind of archiving would be nigh impossible for some businesses, no matter how heavily regulated. Its partially a matter of resource allocation. I do a nightly backup and a monthly backup for an organization that deals with kids, medical records, and large donations (i.e. heavily scrutinized). 80 percent + of donations must be spent on program services, so I have a limited budget. If something is written and deleted betwixt the monthly backup and the earliest nightly, its gone. There's no practical way for me to keep all that data on hand. I recycle the backup tapes and burn DVDs. If I bought enough tapes to keep an independent backup of each day's activity, there'd be no room in my office for me. Nor do I want to spend money on some kind of IM tracker. If I did, those kids with medical conditions would suffer. Sorry lawyers, you'll have keep doing things the ol' fashioned way

  12. Re:Privacy? by Billosaur · · Score: 4, Funny

    More like...

    Auditor: It's not much of a mail server, isn't it?

    Sysadmin: Oh yes, sir, finest in the company sir!

    Auditor: Explain the logic underlying that conclusion, please.

    Sysadmin: Well, it's so clean, sir.

    Auditor: It's certainly uncontaminated by email.

    Sysadmin: You haven't asked me about IMs, sir.

    Auditor: Is it worth it?

    Sysadmin: Could be.

    --
    GetOuttaMySpace - The Anti-Social Network
  13. PLEASE help stop the FUD!!! by spiedrazer · · Score: 3, Informative
    OK everybody, listen up!!

    Despite what the vendors who produce e-mail archiving software may say, there is NO requirement that ANYONE archive all their e-mail/chat/word docs. etc. for potential litigation!!!

    The rules say that, once you know that there is a legal case (or can reasonably expect that an issue may lead to legal action) you can't destroy evidence that could be used in the case. The federal rules actually spend more time outlining all the valid reasons you may have for destroying/deleting old e-mails or other correspondence.

    There are a lot of vendors generating a lot of FUD about this issue, and even more clueless tech writers and glorified corporate publicity rags like eSchool news to perpetuate it. Don't be sucked in!

    Yes, your company/agency should have a retentions policy, but that doesn't mean to retain everything! It should spell out how often you delete materials that are no longer deemed necessary. As long as you follow that policy, you are covered if you delete something that comes up later in an un-anticipated legal action! Once you are aware of a legal action, it is your responsibility to identify and secure any documentation in any form that can have bearing on the case.

    --
    Keep passing the open windows...
  14. The pains of E-Discovery Rules by HeliosTrick · · Score: 2, Interesting

    I'm the sysadmin at a lawfirm in the Chicagoland area, and we've been following these guidelines for a couple years. However, it is quite a hassle, even though we only have 150 employees. We keep tape backups on a rotating 14-day schedule, with End of Month and End of Year retains kept indefinitely - offsite in a fireproof safe, natch. The amount of storage space we need will soon require us to move from LTO-2 to LTO-4 format and buy an even larger safe.

    Most companies may not need to follow these guidelines, but in the legal industry we're literally in court all the time, and it's in our best interest to do so - regardless of headaches it may cause. :)

  15. Internal insight not necessary to regulate. by Kadin2048 · · Score: 2, Informative

    You could just stop caring about internal documents and eliminate or change the laws that depend on them. Treat the corporation as a 'black box,' in other words.

    I'm not sure why we should really give a shit about what goes on inside a company. What matters is what it does. If a corporation does something bad, punish it. I don't really care, and I don't think it should matter, whether people in the corporation "knew" what they were doing was bad, and that's mainly what the retention laws are all about. They exist in order to make it easier to pin down when so-and-so knew something. If you just tell companies you don't care, and enforce rigorous strict-liability doctrine (on the corporation -- I don't really agree with strict liability as applied to individuals, but that's a separate discussion), you can leave the internal policing to the corporations themselves.

    The idea is that basically, you make the corporations responsible for the actions their employees take in their name and the results of those actions, whether intentional or not, and whether the harm was foreseeable or not. Leave it up to them to decide how they want to manage risk and how much freedom they want to give employees to act without authorization.

    I don't really see why we need to peer into companies in order to regulate them. If a company wants to keep its financial records in cuneiform impressed on wads of sodden toilet paper, that's fine by me. The market will punish them for it when nobody wants to buy their stock because there's no way to gain any insight into their performance. Maybe the stock exchanges would even enforce minimum accounting standards for listed companies, as a way of keeping the crap out. But caveat emptor -- do your own research, and don't come whining to anyone else if you put all your money into a company that implodes. If you want secure investments, that's what savings accounts are for.

    Similarly, if a company pollutes or otherwise externalizes costs on the public, punish it. If they don't cough up payment for the externality, forcibly seize whatever physical assets they have under their direct control and sell them at auction.

    I can train my dog without knowing exactly what's going on in his head every moment; that's exactly the philosophy I'd apply to corporate governance. Reward good overall corporate behavior, punish overall bad behavior with meaningful sanctions (asset forfeiture and seizure), and let them do whatever the hell they want internally.

    --
    "Ladies and gentlemen, my killbot features Lotus Notes and a machine gun. It is the finest available."
    1. Re:Internal insight not necessary to regulate. by Cally · · Score: 2, Insightful

      I'm not sure why we should really give a shit about what goes on inside a company. What matters is what it does. Well IANAL so I can't give you a formal answer to that. However it doesn't take much thought to imagine a scenario where whether or not people inside the company knew certain things or not, and when they knew them, has significance regarding how long people go to jail, how much the company's fined, or whatever. As a random though experiment, supposing the wing falls off the fancy new Airbus super-jumbo and 800 people end up getting their 15 minutes of fame in the form of charred shreds of flesh hanging from scorched trees, Paris '74 style. That would be bad, and clearly a lot of questions would be asked, like "why did the wing fall off?" Supposing the investigators find it was a known design weakness and that senior management had deliberately suppressed internal whistle-blowers who tried to flag it as potentially dangerous. In those circumstances, obviously you want those in the know doing 10-30 for each life lost. OTOH, if the failure mode were due to some exotic combination of novel materials and a sequence of unexpected and completely unpredictable events, and world-class engineers universally failed to predict or imagine such an event happening, then it would be rather unfair to clap the Board in irons for negligence. That's why corps can't be black boxes.

      On a completely unrelated note I finally found where your sig comes from last night, and all I can say is: bite my splintery wooden ass!

      --
      "None are more hopelessly enslaved than those who falsely believe they are free." -- Goethe
  16. pretty obviously unenforceable by HelloKitty · · Score: 2, Insightful


    it's a bullshit law. so there's no reason to follow it.
    there's always denyability (i.e. we don't allow IM, so there is no record of it, because it doesn't exist)...
    there's also the "don't incriminate yourself" thing (right to remain silent).

    while we're at it, maybe I should record all conversations I have too. just in case some one want to see wat I've been saying.
    and my brain waves. just in case some lawyer needs to see if I was thinking impure thoughts over the last year.

    like i said. stupid law.

    1. Re:pretty obviously unenforceable by RMH101 · · Score: 2, Informative

      You may argue with the law, but if you ignore it you could end up in prison. As could your CIO. Right or wrong, you'd be stupid to ignore it if you're a company that trades in the US.

  17. why not just record our thoughts "for the record"? by HelloKitty · · Score: 3, Insightful

    while we're at it, maybe I should record all conversations I have too. just in case someone wants to know what I've been saying. you just never know.

    and my brain waves too. just in case some lawyer needs to see if I was thinking impure thoughts over the last year.

    I think we could all accept an implanted recording device in our skulls, don't you?

  18. Ones being investigated for a crime. by pavon · · Score: 4, Informative

    This ruling is about what is and isn't considered destruction of evidence in a court case. The only business which may be required to retain more data that they already would are those who are being investigated for a crime. There are two parts.

    The first deals with data deleted prior to the start of an investigation. Basically if you have an data retention plan that states how long you keep documents for, and you follow that plan, then you cannot be charged with destruction of evidence. On the other hand if a bunch of documents relevant to an investigation just happen to be deleted in a manner that deviates from your normal behavior, then you can be.

    It doesn't matter what the plan is - it could be that you delete emails from the server immediately after they are download, or you can back them up for eternity, or anything in between - it is entirely up to you. For the sake of CYA, it is a good idea to have this policy documented, and to make sure it is followed closely, but you are not required by law to do so.

    The second part gives judges the ability to require companies to retain data relevant to an investigation that would otherwise be deleted as part of their normal data retention policy. This requires a court order, and is no different from dead-tree requirements. Again, you are not required by law to have a plan in place to do this, however, it is good idea to think about it so that you aren't scrambling to figure out how to deal with it if you ever are investigated.