June 16, 2026

What is ESI discovery?

Learn what ESI discovery is, how the EDRM process works, and how to build an ESI protocol that avoids spoliation risks and costly sanctions.

Amanda Fong

Today, most information is created, shared, and stored electronically. That shift has made electronically stored information (ESI) central to how litigation works. Whether you're responding to a discovery request or issuing one, understanding what ESI discovery is, what it involves, and how to manage it effectively is no longer optional for legal professionals.

What is ESI?

ESI stands for electronically stored information. It refers to any data created, stored, or transmitted in electronic form that may be relevant to a legal proceeding. Examples of ESI include, but are not limited to:

  • Emails and their attachments
  • Word processing documents
  • Spreadsheets
  • Databases
  • Text messages
  • Social media content
  • Photos, videos, and audio files
  • Metadata

That last one is worth noting: metadata — the data about data — is itself considered ESI. It tells the story behind a document: who created it, when it was modified, who had access to it. It can be just as important as the document itself, and just as easily destroyed if ESI isn't collected properly.

What is ESI discovery?

ESI discovery is the process of identifying, collecting, preserving, reviewing, and producing electronically stored information in response to legal requirements. It's how parties in litigation exchange the digital evidence relevant to a case.

"Discovery" is the umbrella term for all evidence exchange in litigation — traditionally that meant paper documents, physical records, depositions. As business records moved almost entirely into digital formats, the electronic subset of discovery became the dominant concern, and two terms emerged to describe it: ediscovery (industry shorthand) and ESI discovery (drawn from the Federal Rules' language around "electronically stored information").

For most purposes they're interchangeable, but there's a subtle distinction worth noting: eDiscovery typically refers to the litigation context specifically, while ESI discovery could be read more broadly to encompass any situation where electronically stored information needs to be identified, collected, and reviewed — including internal investigations, regulatory inquiries, and compliance audits. In practice though, the underlying process is functionally the same regardless of what you call it.

What does matter is understanding that ESI discovery is governed by rules of civil procedure and agreed-upon processes, and typically involves reviewing data for privilege and relevance before it is turned over to the requesting party.

The ESI discovery process

ESI moves through several stages from identification to production. The Electronic Discovery Reference Model (EDRM) is the widely accepted framework for understanding that lifecycle:

Information governance — Before litigation even begins, organizations that manage their data well are in a far better position when discovery obligations arise. Poor information governance is one of the leading contributors to discovery disputes and sanctions.

Identification — Once litigation is reasonably anticipated, the first step is identifying where potentially relevant ESI lives: which custodians, which devices, which platforms, and which date ranges.

Preservation — Once identified, relevant ESI must be preserved. This typically means issuing a litigation hold to suspend routine deletion policies for relevant custodians. Waiting too long to issue a litigation hold is one of the most common and costly mistakes in ediscovery.

Collection — ESI must be collected in a forensically sound manner to avoid altering evidence. Collection can be handled by IT staff, outside vendors, or a combination — each approach carries different risks and costs.

Processing — Raw ESI is processed into a reviewable format. This typically includes deduplication, filtering by date range or search terms, and converting files into formats a review platform can read.

Review — Legal teams examine the processed data to identify what's relevant, flag privileged materials, and assess significance to the case. This is often the most time- and resource-intensive stage.

Production — Relevant, non-privileged ESI is produced to the requesting party in an agreed-upon format, in compliance with legal and procedural requirements.

While the EDRM is the widely accepted framework for ESI discovery, Nextpoint and ediscovery expert Tom O'Connor developed their own model in their book eDiscovery for the Rest of Us — the eDiscovery Checklist Manifesto (EDCM).

The EDCM builds on the EDRM with an important addition: a dedicated Conference stage, positioned between preservation and collection. This stage covers the Rule 26(f) Meet and Confer and any other formal or informal discussions with opposing counsel about how ESI will be exchanged — metadata specifications, production formats, search terms, date ranges, and the technology that will be used.

It's worth noting that the EDCM treats the entire process as iterative, not linear: You may cycle back to earlier stages as the scope of the matter evolves or your understanding of the data sharpens.

We think the Conference stage deserves its own place in the workflow because what gets agreed upon there sets the foundation for everything that follows — which is exactly why having a well-drafted ESI protocol matters.

What is an ESI protocol?

An ESI protocol, also known as a discovery protocol or ESI agreement, is a formal agreement between parties in a lawsuit that outlines the processes, procedures, and timeline for exchanging ESI.

Ideally, parties enter into an ESI agreement at the outset of litigation while complying with Rule 26(f) Meet and Confer requirements and similar state regulations. Even if a formal conference isn't required in your jurisdiction, we recommend having one anyway — getting ahead of ESI issues before they arise is far less costly than resolving disputes about data formats, missing metadata, or spoliation after the fact.

Firms that build clear ESI protocols early experience less friction, less unnecessary motion practice, and happier judges. It also helps internally: A solid protocol gives paralegals, associates, and new hires a consistent framework to follow from case to case, rather than reinventing the wheel every time.

There are two related but distinct documents to prepare:

  • Internal ESI protocol: How is ESI collected, reviewed, and produced within your firm?
  • External ESI protocol: How will each party access and produce ESI to the other side?

A well-drafted ESI protocol typically covers the following, all of which are subject to forensic collection:

  • Devices or accounts in scope
  • Custodians
  • Relevant date ranges
  • Search terms
  • Data types and production formats, including relevant metadata
  • Privilege log format and timing
  • Review technology (e.g., TAR, predictive coding, genAI)
  • Definitions — what counts as a "document"? What about email attachments and hyperlinked files?

Common ESI discovery challenges

Even with a well-drafted ESI protocol in place, managing electronically stored information in litigation is rarely straightforward. Below are the most common challenges attorneys and legal professionals face today.

Data volume and unique file types

The sheer volume of modern ESI is one challenge; the variety is another. Beyond emails and documents, legal teams today must contend with Slack and Microsoft Teams messages, social media content, cloud-based files, text messages, and data from mobile devices — each with its own collection requirements, metadata considerations, and format quirks. Without a clear strategy, the cost and time of collection and review can spiral quickly.

Read: How to master ediscovery for Slack, Teams, and other collaboration apps →

Identifying all relevant data sources

Relevant data can be spread across employee devices, corporate servers, third-party cloud platforms, personal email accounts, and social media. Identifying every potential data source is one of the earliest and most consequential challenges in ESI discovery.

Preservation and spoliation risks

If data gets deleted, overwritten, or lost — even accidentally — it can be considered spoliation of evidence. The fallout can be severe, ranging from court sanctions to adverse inference instructions that tell the jury to assume the missing data was harmful to your case.

Read: Defensible deletion vs. defensible storage: what's the difference? →

Metadata preservation

Metadata can be just as important as the document itself, and just as easily destroyed if ESI isn't collected using proper forensic methods.

Read: Real-world case study: how metadata turned photos into courtroom proof →

Inaccessible or legacy data

Old backup tapes, archived databases, and files stored in outdated systems can require serious technical resources to retrieve and process. This tends to catch people off guard, especially in cases involving older companies or long-running business relationships where relevant data may stretch back years.

Hyperlinked files

As cloud-based documents replace traditional email attachments, disputes over whether hyperlinked files should be treated as part of a document "family" have become common. Courts have generally not found equivalency between hyperlinked documents and traditional attachments, but the case law remains unsettled — making it essential to address this explicitly in your ESI protocol.

Read: Modern attachments in ediscovery: what you need to know about hyperlinked files →

Privilege review at scale

Reviewing for attorney-client privilege and work product protection across hundreds of thousands of documents is a massive undertaking. Many legal teams now rely on technology-assisted review (TAR) and AI-powered tools to manage volume, though those tools come with their own questions around accuracy and defensibility.

Download: Protecting Privilege in eDiscovery Checklist →

Cross-border and privacy considerations

If your case involves parties or data across multiple countries, things get complicated fast. Laws like the EU's General Data Protection Regulation (GDPR) can conflict directly with U.S. discovery obligations, requiring careful coordination between litigation counsel and privacy counsel.

Each of these challenges has its own set of best practices and solutions — many of which come down to preparation. A well-drafted ESI protocol addresses the most common friction points before they become disputes: defining custodians and data sources upfront, agreeing on formats and metadata requirements, and establishing clear preservation obligations. On the technology side, purpose-built ediscovery software gives legal teams the tools to collect, process, review, and produce ESI defensibly — without the cost and complexity of cobbling together multiple vendors.

ESI best practices: What's changed and what to know now

The core principles of ESI discovery haven't changed much since ediscovery became standard practice. But the landscape has shifted significantly in the past few years, and some developments are too important to ignore.

AI has created new forms of ESI — and new authentication challenges

Generative AI has introduced a category of ESI that didn't exist a few years ago: AI-generated or AI-manipulated audio, video, images, and documents designed to appear real. Deepfakes and synthetic media are already showing up in litigation, and authenticating them requires a different approach than traditional ESI. Native file collection, chain-of-custody logs, and metadata preservation — EXIF data, codec data, file system metadata — are essential for establishing whether media has been manipulated. There is no single definitive test for detecting deepfakes; forensic verification requires triangulating multiple signals and, increasingly, specialized experts.

Read: How to detect and challenge deepfake evidence in litigation →

Beyond authentication challenges, AI tools are now being used in the review process itself — for document review automation, summarization, and more. Courts are paying close attention. At least 35 standing orders now require disclosure of AI use in court submissions, and in Kohls v. Ellison (D. Minn. 2025), a court excluded expert testimony after AI-generated fake citations appeared in written submissions. ESI protocols should address both dimensions: how potentially AI-generated evidence will be handled, and whether and how AI tools will be used in the review process.

Ephemeral messaging and collaboration platforms are now standard data sources

Slack, Microsoft Teams, Signal, and similar platforms are now standard custodian data sources, but many ESI protocols still don't address them explicitly. A modern approach to ESI discovery should account for how ephemeral and collaboration-based data will be collected, whether conversation threading and metadata will be preserved, and how these sources factor into production obligations.

Data privacy regulations are reshaping ESI discovery obligations

Data privacy has become one of the most significant complicating factors in ESI discovery. The proliferation of privacy regulations — GDPR in the EU, CCPA in California, and a growing patchwork of state-level laws — can create direct conflicts with U.S. discovery obligations. Cross-border cases require careful coordination between litigation counsel and privacy counsel, and even domestic cases increasingly involve sensitive personal data that triggers privacy considerations around how ESI is collected, stored, transferred, and produced. Building data security and privacy compliance into your ESI process from the start — not as an afterthought — is now table stakes.

Get started with ESI discovery the right way

ESI discovery is one of those areas where the work you put in at the beginning of a case pays dividends throughout. A clear, well-negotiated ESI protocol reduces the risk of sanctions, keeps discovery costs in check, and gives your entire team a consistent framework to follow.

Nextpoint's cloud-based ediscovery platform is built to handle every stage of the ESI discovery process — from collection and processing through review and production — with the security, auditability, and native file preservation that modern litigation demands.


FAQs

What is ESI discovery?

ESI discovery is the process of identifying, collecting, preserving, reviewing, and producing electronically stored information (ESI) in response to legal requirements. It's how parties in litigation — and in investigations, regulatory matters, and compliance contexts — manage and exchange digital evidence. The terms ESI discovery and eDiscovery are often used interchangeably; both refer to the same underlying practice of handling electronically stored information in legal proceedings.

What does ESI stand for?

ESI stands for electronically stored information — any data created, stored, or transmitted electronically that may be relevant to a legal proceeding, from emails and spreadsheets to text messages, databases, and metadata.

What is the difference between eDiscovery and ESI?

eDiscovery is the process; ESI is the material. eDiscovery refers to the identification, collection, review, and production of electronically stored information in litigation or investigations. ESI is the actual electronic data exchanged between parties during that process. In practice, the terms are often used interchangeably.

When does the duty to preserve ESI begin?

The duty to preserve ESI is triggered the moment litigation is reasonably anticipated. Waiting too long to issue a litigation hold is one of the most common and costly mistakes in ediscovery.

What happens if ESI is not properly preserved?

Failure to preserve relevant ESI can constitute spoliation of evidence. Consequences range from court sanctions and monetary penalties to adverse inference jury instructions, where the jury is told to assume the missing data would have been harmful to your case.

How should generative AI be addressed in an ESI protocol?

At minimum, your ESI protocol should disclose whether AI tools will be used in the review process, how those tools will be validated, and how human oversight will be maintained. Courts are increasingly issuing standing orders requiring AI disclosure, and failing to address it upfront can create defensibility issues down the line.

What are ephemeral messages and do they need to be preserved?

Ephemeral messages are communications designed to disappear after being read or after a set period — think disappearing messages on Signal or certain Slack configurations. Once a litigation hold is issued, steps should be taken to suspend auto-delete functions for relevant custodians.

Join our Nextpoint newsletter list

recommendation

Related Resources

Blog

Blog

Seven Characteristics of Law Firms Who Are Legal Technology Rockstars

Law firms that successfully use better legal technology gain a competitive advantage. Here's our list of what makes a "technology rockstar."

Blog

Blog

Nextpoint Acquires WarRoom from LaunchPad Lab

eDiscovery and litigation support leader acquires modern deposition transcript platform to integrate platforms and enhance customer value.

Blog

Blog

eDiscovery Day 2023: Top Resources from Nextpoint This Year

For eDiscovery Day 2023, we're sharing the highlights of our year – including our top ediscovery resources and tips.

No items found.
READY TO GET STARTED?

Experience Nextpoint for yourself

Learn how our transparent pricing and powerful platform help legal teams streamline litigation from discovery to decision.