Summary. Electronic discovery consumes litigation budgets, and the decisions that determine the cost are made in the first sixty days by lawyers negotiating a document most have never drafted carefully. This guide covers the ESI protocol clause by clause: the meet-and-confer obligation and the proportionality standard framing every dispute; the scope decisions driving volume — custodians, date ranges, and data sources, including the collaboration platforms and messaging applications that now hold what email used to; search methodology including keyword negotiation and TAR; production format specifications; privilege logging and the Rule 502(d) order; inaccessible sources and cost shifting; and preservation failures.
Two companies litigate a $6 million contract dispute. Neither side negotiates an ESI protocol; each serves requests for production and objects to the other's.
The plaintiff collects from 24 custodians across a five-year period, applies no search terms because "we want to be thorough," and produces 1.9 million pages as static images with no metadata and no load file. The defendant cannot sort by date, cannot identify who sent what, cannot thread the emails, and cannot load the production into a review platform. It moves to compel a re-production.
The defendant, meanwhile, produced only from email. It did not collect from the collaboration platform where the project team actually communicated, because nobody asked and nobody volunteered. Eight months later a deposition reveals the platform's existence, producing a motion, a re-collection, and a request for sanctions.
Combined e-discovery cost across both sides: approximately $1.4 million on a $6 million case. The overwhelming majority of it was avoidable, and all of it was determined by decisions made — or not made — in the first two months.
The ESI protocol is the cheapest cost-control document in litigation. It is also the one most often copied from a form and signed without analysis.
The framework
Rule 26(f) requires the parties to confer before the scheduling conference and to discuss any issues about disclosure, discovery, or preservation of electronically stored information, including the form or forms in which it should be produced, and any issues about claims of privilege or protection, including whether to ask the court to include their agreement in an order under Federal Rule of Evidence 502.
Rule 16(b)(3)(B) permits the scheduling order to provide for disclosure, discovery, or preservation of ESI and to include agreements reached under Rule 502.
Rule 26(b)(1) — the proportionality standard, which frames every ESI dispute. Discovery must be relevant to a party's claim or defense and proportional to the needs of the case, considering:
- The importance of the issues at stake in the action;
- The amount in controversy;
- The parties' relative access to relevant information;
- The parties' resources;
- The importance of the discovery in resolving the issues; and
- Whether the burden or expense of the proposed discovery outweighs its likely benefit.
The 2015 amendment moved proportionality into the definition of the scope of discovery, so it is not an objection to be raised but a limit built into the entitlement. In practice this means an ESI dispute is won with data: custodian counts, hit reports, gigabyte volumes, review-hour estimates, and cost figures.
Rule 26(b)(2)(B) — a party need not provide discovery of ESI from sources it identifies as not reasonably accessible because of undue burden or cost. On a motion, the responding party bears the burden of showing inaccessibility; the court may nonetheless order discovery on a showing of good cause, and may specify conditions including cost allocation.
Rule 34(b) — the requesting party may specify the form or forms of production; the responding party may object and state the form it intends to use; and absent specification, ESI must be produced in the form in which it is ordinarily maintained or in a reasonably usable form. A party need not produce the same ESI in more than one form.
Rule 37(e) governs failure to preserve ESI, discussed at the end.
The meet and confer
Do not send a lawyer who does not understand the client's systems. The single most common failure in ESI negotiation is a conference between two litigators, neither of whom can answer a question about where the data lives. Bring — or at minimum debrief thoroughly — someone from IT.
Before the conference, know your own environment:
- What email system, and what retention policy.
- What collaboration platforms — Slack, Teams, Google Workspace — and their retention settings.
- What file storage — network shares, SharePoint, OneDrive, Google Drive, Box.
- What structured systems — ERP, CRM, ticketing, financial, and their export capabilities.
- Whether mobile devices are company-issued or personal, whether an MDM exists, and whether text and messaging data is captured.
- Whether ephemeral or encrypted messaging is used, and with what retention.
- Backup architecture and restoration cost.
- Legacy systems and departed-employee data.
- What has already been preserved and when the hold issued.
Agenda for the conference:
- Preservation — scope, when holds issued, and any sources not preserved.
- Custodians and how they will be identified.
- Data sources, including non-email sources.
- Date range.
- Search methodology — terms, TAR, or a combination.
- Production format and metadata.
- Deduplication and threading.
- Privilege logging format and scope.
- Rule 502(d) order.
- Inaccessible sources and any cost allocation.
- Phasing, timing, and rolling production schedule.
- Dispute resolution process short of motion practice.
Confirm every agreement in writing immediately after the conference, and reduce the whole thing to a stipulated protocol entered as an order. An agreement not entered as an order is far harder to enforce, and a Rule 502(d) provision must be an order to have its principal effect.
Scope: custodians, sources, and date range
Custodians drive volume more than any other variable.
How to identify them: organizational charts, the client's own knowledge, the initial disclosures, the documents already known, and — where the parties cannot agree — a limited set of custodian questionnaires or a deposition of a Rule 30(b)(6) witness on data sources.
The negotiation: a requesting party names everyone; a responding party names three. The workable structure is tiered:
- A core group collected and reviewed at the outset.
- A secondary group collected and preserved but not reviewed unless the core production shows a need.
- A defined process for adding custodians, with a limited number added on a showing based on the production.
That structure resolves most custodian fights, because it defers the argument until there is evidence rather than speculation.
Date range. Anchor it to the events, not to the relationship. A five-year range in a dispute about a six-month project is unjustifiable, and the requesting party asking for it should expect to explain why under Rule 26(b)(1).
Data sources — the part that has changed most. Email is no longer where the conversation happens.
- Collaboration platforms hold the operational discussion. Collection is possible but the export formats vary widely, threads do not map to documents, and the volume is enormous. Negotiate channel-level or conversation-level scoping rather than whole-workspace collection, and agree how a "document" is defined for production and Bates numbering.
- Modern attachments / cloud links. A message containing a link to a cloud file, rather than an attached file, is the current hardest problem. The linked file may have been edited since. The protocol should address whether links are followed, which version is produced, and how the parent-child relationship is preserved in the load file.
- Mobile devices and text messages. Whether company-issued or personal, whether a BYOD policy gives the company access, and what is proportionate. Full forensic imaging of every custodian's phone is rarely proportionate; targeted collection of messages with identified individuals over the date range frequently is.
- Ephemeral and encrypted messaging. Whether it was used, whether retention was enabled, and whether disabling retention after litigation was foreseeable is a preservation problem rather than a collection one.
- Structured data. Do not collect the database; agree on a report or extract with specified fields, or a query the parties define. This is where the most useful evidence in commercial cases frequently lives, and where the least thought is applied.
- Voicemail, video conference recordings and transcripts, and calendar data.
- Third-party and cloud-hosted data in the party's possession, custody, or control — a defined term that turns on the legal right to obtain the data in most circuits, and on practical ability in a minority.
- Social media, where relevant.
Sources the protocol should expressly exclude absent a specific showing, because litigating them individually is wasteful: disaster recovery backup tapes; deleted data requiring forensic recovery; unallocated space and file fragments; system and application logs not used in the ordinary course; RAM and temporary files; and data from devices no longer in the party's possession.
Search methodology
Keyword search remains the most common approach and is the most commonly botched.
How to negotiate terms productively:
- The responding party should propose terms, because it knows the vocabulary of its own business. A requesting party's blind list generates enormous false positives.
- Exchange hit reports showing, for each term, the number of documents hit and the number of unique documents hit. This converts an argument into arithmetic.
- Test and iterate. Terms producing tens of thousands of hits with no unique value should be narrowed with proximity connectors, or dropped.
- Beware generic terms — a company's own name, "contract," "agreement," "problem" — which hit everything.
- Use proximity operators rather than bare AND across an entire document.
- Address stemming, wildcards, and noise words, which behave differently across platforms.
- Address non-searchable documents — image PDFs, scanned files, handwritten notes — which keyword search misses entirely and which require OCR or a separate review of a defined population.
- Agree that a party may supplement terms based on what the production reveals, within a defined limit.
Technology-assisted review (TAR) — predictive coding — uses machine learning to prioritize or classify documents.
- Courts have accepted TAR since Da Silva Moore v. Publicis Groupe, 287 F.R.D. 182 (S.D.N.Y. 2012), and it is now unremarkable. Rio Tinto PLC v. Vale S.A., 306 F.R.D. 125 (S.D.N.Y. 2015), observed that the case law had developed to the point that TAR's acceptability was black letter law.
- Most courts hold that a responding party may choose its own methodology, and that a requesting party cannot dictate TAR or keywords. Hyles v. New York City, 2016 WL 4077114 (S.D.N.Y. Aug. 1, 2016), declined to force a producing party to use TAR over keywords, on the principle that the responding party is best situated to decide how to search.
- The negotiation is therefore usually about transparency and validation rather than about the method: whether seed sets or training decisions are disclosed, what recall and precision the process achieves, and what validation protocol — typically a statistically sound sample of the null set — establishes that responsive documents were not missed.
- Do not agree to produce the seed set without thought; several courts have declined to require it, and it can disclose work product.
Threading and deduplication:
- Deduplication should be global across custodians, not per-custodian, and the protocol should require production of the custodian and duplicate-custodian fields so the requesting party knows who else had the document. Per-custodian deduplication inflates volume enormously.
- Email threading suppresses lesser-included messages within a fully inclusive thread. It reduces review volume dramatically and is standard. The protocol should specify whether suppressed messages are produced and how thread relationships appear in the load file.
- Near-deduplication for documents, with the threshold specified.
What the protocol should say about search: that the responding party will use a reasonable and proportionate methodology; that hit reports will be exchanged for keyword approaches; that the parties will meet and confer on refinements; and — importantly — that use of an agreed methodology satisfies the responding party's obligation absent a showing that it failed. Without that last provision, a party can perform every agreed step and still face a motion arguing it should have done more.
Production format
This is the part of the protocol that determines whether the received documents are usable, and it is the part most often copied without reading.
The main options:
- Native — the original file. Preserves all functionality and metadata; cannot be Bates-stamped on its face or redacted easily.
- Near-native — native for some file types, imaged for others.
- TIFF or PDF images with a load file — the traditional approach: single-page TIFFs (or multi-page PDFs), an extracted text file per document, and a load file (DAT and OPT/LFP) carrying the metadata fields.
- Hybrid — the practical standard: images with extracted text and metadata, with native production for file types that are unusable as images.
Produce natively, at minimum:
- Spreadsheets — an imaged spreadsheet loses formulas, hidden rows and columns, and multiple tabs, and is frequently unreadable.
- Presentations with speaker notes and animations.
- Audio and video files.
- Databases and structured data extracts.
- CAD files and other specialized formats.
Metadata fields to specify — this list is the heart of a usable production:
- BegBates, EndBates, BegAttach, EndAttach (the family relationships)
- Custodian, DuplicateCustodians
- FileName, FileExtension, FileSize
- DocType
- From, To, CC, BCC
- Subject
- DateSent, TimeSent, DateReceived, TimeReceived (with the time zone specified — a protocol that does not specify UTC or a named zone guarantees a dispute)
- DateCreated, DateLastModified, Author, LastModifiedBy
- MD5 or SHA-1 Hash
- Path or SourcePath
- ConversationIndex or ThreadID
- Confidentiality designation
- Redacted (yes/no)
- NativeFileLink and TextLink
- For messaging platforms: Channel or Conversation, Participants, MessageDateTime
Other format specifications:
- Bates numbering — the prefix format, sequential numbering, and endorsement placement.
- Confidentiality legends and how they interact with Bates endorsement.
- Family relationships preserved — attachments produced with their parents, and the parent produced even if only the attachment is responsive (or the reverse, specified).
- Redactions — applied to the image with the corresponding text and metadata redacted, and a field identifying redacted documents. Never produce a native file with a redaction applied only visually.
- Color where color is meaningful.
- OCR for image-only documents.
- Encryption and password-protected files — the responding party's obligation to provide passwords or decrypted versions.
- Delivery — media, secure FTP, or a shared repository, with an encryption standard and a transmittal letter identifying the Bates range, the volume, and the contents.
- Rolling production schedule with defined intervals.
Read the format section as a recipient, not as a producer. Ask: can I load this into my review platform, sort it by date, thread it, and tell who received what? If any answer is no, the specification is wrong.
Privilege logging and the Rule 502(d) order
Rule 26(b)(5)(A) requires a party withholding privileged information to describe the nature of the documents withheld in a manner that, without revealing the protected information, enables other parties to assess the claim.
Document-by-document logs are the default and are enormously expensive in an ESI case — a log entry can cost more than the review of the document.
Alternatives worth negotiating:
- Categorical logs, describing categories of withheld documents rather than individual entries. Courts increasingly permit them for defined categories, particularly communications with outside counsel after a date certain.
- Metadata-based logs generated from the fields already collected, with a limited narrative.
- Date cutoffs — no logging of communications with counsel after the complaint was filed or after a defined trigger date, which is the single most effective cost-reduction agreement available.
- Exclusions — no logging of communications solely between a party and its litigation counsel, or of work product created for this litigation.
- Deferred logging, produced on a schedule after substantial completion rather than with each rolling production.
- Family logging — one entry for a document and its attachments where the privilege claim is the same.
Federal Rule of Evidence 502(d) is the most valuable and most underused provision in electronic discovery.
What it does: a federal court may order that a disclosure of privileged or work-product material in the litigation before it does not operate as a waiver in that proceeding or in any other federal or state proceeding. Critically, a 502(d) order can provide that waiver does not occur regardless of the care taken to prevent disclosure — displacing the Rule 502(b) inadvertence analysis (reasonable steps to prevent and to rectify) entirely.
Why it matters: without a 502(d) order, a producing party that inadvertently produces a privileged document must show it took reasonable steps to prevent disclosure — which invites an argument about the adequacy of its review, and which is the reason parties over-review at enormous cost. With one, the risk of a single missed document is removed, and a party can review faster and produce sooner.
Get one entered in every case. It should be a short, standalone order, not merely a clawback clause in a protective order — several courts have noted that only a court order carries the non-waiver effect against third parties, and that a party agreement does not.
What it should say: that production does not waive privilege or work product in this or any other proceeding; that it applies regardless of the care taken; the procedure and time for a clawback notice; the receiving party's obligation to sequester, return, or destroy and to delete from any database; that the receiving party may challenge the claim by motion without using the document's contents; and that nothing requires a party to produce without review.
Note what it does not do. It does not protect against intentional production, it does not create privilege where none existed, and it does not excuse a party from providing a privilege log.
Inaccessible sources, cost shifting, and phasing
Rule 26(b)(2)(B) — a party may identify sources as not reasonably accessible because of undue burden or cost and need not produce from them absent a court order. The party must still identify the sources by category or type, and the preservation obligation is a separate question.
Typical inaccessible sources: disaster recovery backup tapes requiring restoration; legacy systems whose software no longer runs; data requiring forensic recovery from unallocated space; and data in obsolete formats.
Cost shifting. The presumption is that the responding party bears its own production costs, Oppenheimer Fund, Inc. v. Sanders, 437 U.S. 340 (1978). Shifting is exceptional and is considered where the source is inaccessible. The Zubulake v. UBS Warburg LLC, 217 F.R.D. 309 (S.D.N.Y. 2003), seven-factor test remains the common reference:
- The extent to which the request is specifically tailored to discover relevant information;
- The availability of the information from other sources;
- The total cost of production compared to the amount in controversy;
- The total cost of production compared to the resources available to each party;
- The relative ability of each party to control costs and its incentive to do so;
- The importance of the issues at stake in the litigation; and
- The relative benefits to the parties of obtaining the information.
The 2015 amendments also expressly authorize the court to allocate expenses in a protective order under Rule 26(c)(1)(B), which is a more flexible tool than a formal cost-shifting motion.
Taxation of costs after judgment is narrower than parties expect. Section 1920(4) permits taxing the costs of exemplification and making copies of materials necessarily obtained for use in the case, and most circuits construe this to cover conversion and Bates-stamping but not collection, processing, hosting, review, or project management. A prevailing party should not assume its e-discovery vendor invoice is recoverable.
Phasing is the most effective cost-control technique and is underused:
- Phase 1 — a core custodian set, a narrow date range, and the most probative sources, produced first.
- Phase 2 — expansion based on what Phase 1 shows, with a defined mechanism and limits.
- Tie phases to case milestones — a dispositive motion, a class certification decision, or a mediation — so that expensive discovery is deferred until it is known to be necessary.
Sampling — reviewing a statistically valid sample of a large population to determine whether full review is justified — is available and is accepted, and it converts an argument about burden into evidence.
Preservation and Rule 37(e)
The duty to preserve arises when litigation is reasonably anticipated, which is frequently earlier than the complaint: a demand letter, an internal report of a serious incident, a regulatory inquiry, or a decision to sue.
The scope is what is relevant to the anticipated claims — not everything, and the protocol should reflect a proportionate scope rather than an absolute one.
Rule 37(e) governs failure to preserve ESI that should have been preserved in the anticipation or conduct of litigation, that is lost because a party failed to take reasonable steps to preserve it, and that cannot be restored or replaced through additional discovery. If those conditions are met:
- On a finding of prejudice to another party, the court may order measures no greater than necessary to cure the prejudice.
- Only on a finding that the party acted with the intent to deprive another party of the information's use in the litigation may the court presume the information was unfavorable, instruct the jury it may or must so presume, or dismiss the action or enter a default judgment.
The intent finding is the whole fight. Negligence — even gross negligence — does not support the severe measures. Facts that have supported an intent finding: deleting after a hold issued; disabling a retention policy after litigation was anticipated; wiping a device before turning it over; and using an ephemeral messaging application after a duty attached.
Rule 37(e) applies only to ESI. Loss of tangible evidence remains governed by inherent authority and state law, which in many jurisdictions permits an adverse inference on a lesser showing.
Practical preservation steps that prevent Rule 37(e) exposure:
- Issue the hold promptly and in writing, with acknowledgments.
- Suspend automated deletion at the system level — email purge, chat retention, backup rotation, device wipe on separation — and document the IT actions with timestamps.
- Preserve departing employees' data before offboarding.
- Reissue reminders periodically, and update the hold as the scope changes.
- Document the decisions, including sources deliberately not preserved and why, with the proportionality reasoning.
- Collect early from high-risk custodians rather than relying on individual compliance.
Vendor management and workflow
The cost is in volume and in review hours, and both are controllable.
The cost drivers, in order:
- Review — typically 60 to 80 percent of the total. Driven by document count.
- Hosting — per gigabyte per month, which makes duration matter.
- Processing — per gigabyte ingested.
- Collection — per custodian or per device.
- Production — per page or per gigabyte.
Reduce volume before review:
- Global deduplication and email threading — routinely a 40 to 60 percent reduction combined.
- Date and custodian filtering applied at processing.
- File type filtering — system files, executables, and known-benign files by hash (a NIST list).
- Domain filtering for obvious non-responsive bulk mail.
- Targeted collection rather than full-device imaging where proportionate.
Control review cost:
- TAR or prioritized review, so the responsive documents surface first and the review can stop when the marginal yield drops.
- Clear coding protocols and a small, well-trained review team rather than a large untrained one.
- Quality control sampling rather than second-pass review of everything.
- A 502(d) order, which permits faster privilege review.
- Categorical privilege logging and a date cutoff.
Vendor selection and contracting:
- Get detailed pricing — per GB processing, per GB per month hosting, per hour project management, per page production — and model the total on realistic volume assumptions.
- Address data security, breach notification, and confidentiality; the vendor holds the client's most sensitive material.
- Address data disposition at case end, with a certificate of destruction, and note that hosting fees accrue until data is removed.
- Confirm the vendor can produce in the agreed format before agreeing to the format.
- Confirm defensibility — audit trails, chain of custody, and the ability to testify about the process if challenged.
Track spend against a budget by phase, and report it. An e-discovery budget that is not tracked monthly is not a budget.
A worked example
Halvorsen Industrial v. Kestrel Controls, a $6 million contract and warranty dispute. Counsel negotiate a protocol before the Rule 26(f) conference.
Custodians. Halvorsen proposes 19; Kestrel proposes 4. They agree on a tiered structure: 7 core custodians collected and reviewed; 6 secondary custodians collected and preserved but not reviewed; and a mechanism permitting either party to add up to 3 custodians from the secondary tier on a showing based on the production.
Date range. Thirty months, from six months before the contract through six months after the alleged breach — rather than the five years originally requested.
Sources. Email; the shared network folder for the project; the Teams channel where the engineering team coordinated (channel-scoped, not workspace-wide); the ticketing system (a defined report extract with specified fields rather than the database); and, for two custodians only, text messages with an identified set of counterparties. Backup tapes, forensic recovery, and unallocated space are expressly excluded as not reasonably accessible.
Search. Kestrel proposes 34 terms; hit reports are exchanged. Six terms are dropped for hitting more than 60 percent of the corpus with negligible unique value; four are narrowed with proximity operators. Halvorsen proposes 11 additional terms; hit reports lead to 7 being adopted. Both sides may propose up to 5 supplemental terms after reviewing the first production.
Volume management. Global deduplication across custodians with a DuplicateCustodians field; email threading with suppression of lesser-included messages; file-type and NIST hash filtering. The collected 1.1 terabytes reduces to 340,000 documents for review.
Format. Single-page TIFFs with extracted text, a DAT load file with 27 specified metadata fields and time zone set to UTC, families preserved, natives produced for spreadsheets, presentations, audio, video, and the ticketing extract, redactions applied to image and text with a Redacted field, and rolling productions every three weeks.
Privilege. A Rule 502(d) order entered as a standalone order, providing non-waiver regardless of care taken. Privilege logging on a categorical basis for communications with outside counsel, no logging of communications after the complaint was filed, family-level entries, and the log delivered 30 days after substantial completion.
Phasing. Phase 1 covers the 7 core custodians and email plus the network folder. Teams and text collection is deferred to Phase 2 unless Phase 1 shows a gap — it does, and Phase 2 proceeds by agreement without a motion.
Result. Combined e-discovery cost of roughly $310,000 across both sides, against the $1.4 million spent in the unmanaged version of the same case. Zero discovery motions. The document that produced the difference was fourteen pages and took two lawyers and two IT professionals about six hours to negotiate.
Frequently asked questions
Do we need an ESI protocol in every case? In any case with meaningful electronic discovery, yes. In a small case, a short stipulation covering format, custodians, and a 502(d) order is enough — but the 502(d) order should be entered even in the smallest case.
Can the other side dictate our search methodology? Generally not. Most courts hold the responding party is best situated to choose its method, subject to proportionality and to producing what the rules require.
Should we agree to produce natively? For spreadsheets, presentations, audio, video, and structured extracts, yes — imaged versions are frequently unusable. For everything else, images with text and metadata are the practical standard.
What metadata fields should we demand? At minimum the family fields, custodian, sender and recipients, dates and times with a specified time zone, file name and type, hash, and paths. Without them the production cannot be sorted, threaded, or attributed.
Is a clawback agreement enough? No. Get a Rule 502(d) order, entered by the court, providing non-waiver regardless of the care taken. An agreement alone may not protect against third parties.
Do we have to log every privileged document? Rule 26(b)(5)(A) requires a description enabling assessment of the claim. Negotiate categorical logging, family entries, and a date cutoff — this is the largest single cost item that can be negotiated away.
Who pays? The producing party, presumptively. Cost shifting is exceptional and is generally considered only for sources that are not reasonably accessible.
What if we deleted something? Rule 37(e) applies only if the ESI should have been preserved, reasonable steps were not taken, and it cannot be restored or replaced. Curative measures require prejudice; adverse inference and terminating sanctions require an intent to deprive.
Conclusion
Electronic discovery costs what the parties decide it will cost, and they decide in the first sixty days.
Four provisions carry most of the value. A tiered custodian structure with a mechanism for adding, which defers the biggest volume fight until there is evidence. A metadata specification detailed enough that the received production is actually usable. A Rule 502(d) order entered by the court, which removes the risk that drives over-review. And negotiated privilege logging with a date cutoff, which eliminates the single most expensive line item that has nothing to do with the merits.
None of that requires expertise in information technology. It requires a conversation with the client's IT staff before the Rule 26(f) conference, and a willingness to negotiate a document rather than sign a form.
Related articles
- Discovery Toolkit — the broader discovery sequence.
- Litigation Holds, Spoliation, and Rule 37(e) — preservation in detail.
- Litigation Hold and Evidence Preservation Checklist — the operational steps.
- Mastering Document Discovery — responding to requests.
- Preparing a Privilege Log: A Practical Checklist — logging mechanics.
- Attorney-Client Privilege and Work Product for Businesses — the privilege being logged.
- Motion Practice Toolkit — discovery motions and the meet-and-confer record.
- Responding to a Government Subpoena or Civil Investigative Demand — collection and production for the government.
- Employee Monitoring and Workplace Privacy — the data sources and their retention.
- Federal Civil Litigation Toolkit — where discovery sits in the case.
This guide is provided for general informational purposes and does not constitute legal advice. Discovery practice varies by district and by judge, standing orders frequently impose additional ESI requirements, and technology changes faster than the rules. Consult qualified litigation counsel and the court's standing orders before the Rule 26(f) conference.