In 2016 a preservation instruction typically covered a mailbox, a laptop and a share drive. In 2026 the equivalent instruction covers a Microsoft 365 or Google Workspace tenant with a dozen linked apps, a mobile phone with a personal and a work profile, a SaaS platform used by the sales team, a chat app used by the engineering team, a cloud storage account personally provisioned by the executive assistant, and a set of ephemeral messaging channels nobody in-house is willing to identify by name. The obligation is identical. The execution is not.
A workable preservation programme
- 01Written litigation hold. Names the custodians, mailboxes, devices, cloud tenants and third-party services in scope. Acknowledged in writing by the recipients. Reviewed at defined intervals as the matter develops.
- 02Data map. A one-page (or one-tab) inventory of where relevant material actually lives for the custodians in scope: work-issued device, personal device used for work, sanctioned cloud, shadow-IT services in use. Built with the custodians, not for them.
- 03Suspension of retention and disappearing-message settings. In place across the identified sources. Signal auto-delete disabled, WhatsApp disappearing messages disabled, Slack retention paused, tenant retention policies overridden by hold.
- 04Forensic acquisitions of the crown-jewel sources. Devices imaged, cloud tenants exported natively, key SaaS platforms exported through their native admin tooling. Hashed, sealed and stored — before user-side change can occur.
- 05Contemporaneous custody log. Kept from the moment each item comes into the party's control: what was preserved, when, by whom, and under what authority.
Where relevant material now lives — and how to preserve it
| Source | Typical preservation route |
|---|---|
| Microsoft 365 / Google Workspace mailboxes | In-Place / Litigation Hold, or Google Vault hold + native export |
| Cloud storage (OneDrive, Google Drive, Dropbox, Box) | Admin-level export with retention hold, hash-verified |
| Chat platforms (Teams, Slack, Google Chat) | Retention hold + native compliance export via admin tooling |
| Mobile devices (personal and work) | Forensic acquisition, method matched to case (see the extraction ladder) |
| Ephemeral messaging (WhatsApp, Signal, Telegram) | Consented device acquisition; account-level takeout where supported |
| SaaS platforms (CRM, HR, project tools) | Native admin export, ideally with audit-log preservation |
| Shadow-IT services (personally-provisioned tools) | Written custodian direction to preserve; scoped acquisition if disputed |
What has changed in the last twenty-four months
- Disappearing-message features are now default in several messenger apps — active preservation steps are needed even to keep messages in scope.
- AI assistants embedded in productivity tools generate their own material (prompts, generated content, activity logs) that increasingly falls within disclosure.
- Cross-tenant collaboration (external guests in Teams/Workspace) means relevant material can live in an organisation the party does not administer.
- Personal-device use for work is normalised, and preservation of a custodian's own phone under written authority is now a routine — not exceptional — instruction.
- Cloud-tenant audit-log retention defaults remain short (90 days is still typical); evidence of who did what, when, has a short half-life without an active hold.
What has not changed
The duty. If proceedings are in reasonable contemplation, potentially relevant material must be preserved — irrespective of platform, ownership or ease of access. The consequences of failing to preserve have if anything sharpened: adverse inferences, costs orders, wasted-costs applications against those responsible, and — in regulated sectors — separate enforcement exposure. The courts are increasingly explicit that ignorance of where the data lives is not a defence to failure to preserve it.
The document that most reliably protects an organisation from a spoliation argument is a short, contemporaneous decision log — kept as the preservation programme is executed, not reconstructed months later when the argument arises.
What the courts are increasingly asking
Not just what was preserved, but when the duty arose, what steps were taken in response to that trigger, who took them, and why anything relevant was not preserved. A short paper trail, kept contemporaneously, is worth an order of magnitude more than a long explanation reconstructed after the fact. Instructing an examiner early — even if only to advise on the scope of the hold — is almost always cheaper than defending a preservation failure in front of a tribunal later.
Frequently asked questions
When litigation is in reasonable contemplation — not when it is issued. The trigger is fact-specific and often earlier than clients assume; a solicitor's letter of claim, an internal grievance, or a regulator's enquiry can each be sufficient.
Where personal devices have been used for work in a manner that puts relevant material on them, yes. Preservation is achieved by written direction to the custodian and, where content is disputed, by scoped forensic acquisition under consent or order.
Auto-delete features must be disabled on relevant channels as soon as the duty arises. Failure to do so, once contemplation is on foot, is a preservation failure whether or not the deletion was deliberate.
Only in the narrow window their default policies cover — typically 30–90 days for audit logs and 30 days for deleted-item recovery. Active holds through the provider's compliance tooling are required to preserve beyond the default window.
Instruct external counsel and a forensic examiner immediately. There is still material that can be recovered — from server-side backups, tenant audit logs, and unaltered secondary sources — and a documented catch-up is better than a continued failure.
