When opposing counsel challenges your data collection methodology, you need more than good intentions. You need documentation, repeatable processes, and proof that you preserved what the court ordered. This checklist guides you through the core requirements of a defensible collection process, based on what holds up under scrutiny.
Data collection ranked as the second most common firm-level challenge in Nextpoint's 2026 eDiscovery Landscape Survey, cited by 34% of respondents. The stakes are clear: collection failures lead to spoliation motions, adverse inference instructions, and sanctions. This isn't about theoretical risk. It's about what happens when you can't explain how you collected, what you missed, and why.
Prerequisites
Before you use this checklist, confirm you have:
A triggering event that creates a duty to preserve. This could be a filed complaint, a credible threat of litigation, or a regulatory investigation notice. Without a clear trigger, you don't yet have a preservation obligation.
Authority to issue legal holds. Verify who in your organization can authorize holds and collections. If you're outside counsel, confirm your client contact has the authority to direct custodians.
Access to IT and custodian contacts. You'll need cooperation from IT to map data sources and from custodians to confirm hold compliance. Line up those contacts now.
Collection Checklist
1. Data Source Mapping
Requirement: Document all locations where potentially relevant data exists before collection begins.
Action: Create a written inventory that includes email servers, cloud storage platforms (Office 365, Google Workspace), collaboration tools (Slack, Teams), mobile devices, third-party platforms, and shared drives. For each source, note the custodian, data type, and collection method you'll use.
What good looks like: You can hand opposing counsel a dated document showing every data source you identified, when you identified it, and how you determined scope. Gaps discovered upfront and documented are defensible. Gaps discovered mid-litigation are not.
2. Legal Hold Issuance and Acknowledgment
Requirement: Issue written litigation holds to all custodians and document their receipt and understanding.
Action: Send hold notices in writing with clear instructions on what to preserve and what not to delete. Require custodians to acknowledge receipt. Track who acknowledged, who didn't, and when you followed up.
What good looks like: Your hold log shows the date issued, the custodians notified, acknowledgment dates, and follow-up dates for non-responders. A litigation hold is only as good as its implementation, and courts have little patience for spoliation arguments stemming from poorly monitored hold notices.
3. Hold Monitoring and Re-Issuance
Requirement: Confirm custodians are actually preserving data and re-issue holds as needed.
Action: Schedule follow-up interviews or surveys with custodians 30 days after initial hold issuance. Ask: Have you preserved the data? Have you stopped auto-delete routines? Are there new data sources we didn't identify? Re-issue holds when new custodians are identified or when the matter scope changes.
What good looks like: Your file includes dated notes from custodian check-ins and updated hold notices reflecting scope changes. You can demonstrate active monitoring, not passive hope.
4. Native Format Collection
Requirement: Collect files in their native format to preserve metadata.
Action: Use collection tools that capture native files with full metadata intact (created date, modified date, author, file path). Avoid printing to PDF or taking screenshots except when native collection is technically impossible.
What good looks like: Your collection includes .msg files for emails, .docx files for Word documents, and .xlsx files for spreadsheets. You can produce metadata reports showing file creation dates, authors, and modification history. This metadata is essential for authentication, privilege analysis, and timeline construction.
5. Chain of Custody Documentation
Requirement: Document who collected data, when, how, and from where.
Action: For each collection event, record the date, the custodian or data source, the tool or method used, the person who performed the collection, and the location where collected data was stored. If you used forensic imaging, note the hash values.
What good looks like: Your collection log reads like a lab notebook: specific, dated, and signed. If you're asked in a deposition how you collected custodian X's email, you can cite the exact date, method, and tool without reconstructing from memory.
6. Collection Scope Decisions
Requirement: Document date ranges, search terms, and custodian scope decisions.
Action: Write down why you chose the date range you chose, why you included or excluded certain custodians, and what search terms or filters you applied. If you limited collection to certain file types, document that decision and the rationale.
What good looks like: Your file includes a memo or log entry explaining: "We limited collection to January 1, 2024, present because the alleged conduct began in Q1 2024 per the complaint. We excluded custodian Y because they left the company in 2023 and had no involvement in the transaction at issue."
7. Quality Verification
Requirement: Verify that the collection actually captured what you intended to capture.
Action: Run a sample review of collected data. Check file counts against expected volumes. Confirm metadata populated correctly. If you collected 50,000 emails but expected 200,000, investigate the gap before you certify the collection as complete.
What good looks like: Your collection report includes a verification step with notes like: "Reviewed sample of 100 files. Metadata fields populated correctly. File count consistent with custodian estimates. No anomalies detected."
Common Mistakes
Treating the hold notice as the end of the process. Issuing the notice is step one. Monitoring compliance is step two. Many teams skip step two and discover preservation failures only when it's too late.
Collecting processed files instead of native files. PDFs and TIFFs strip metadata. You lose created dates, modification history, and embedded comments. Collect natively unless technically impossible.
Failing to document scope decisions in real time. If you exclude a custodian or data source, write down why at the time you make the decision. Reconstructing your reasoning six months later during a sanctions hearing is unconvincing.
Using ad hoc methods that change from matter to matter. Inconsistent processes are indefensible processes. Build a repeatable workflow and document deviations, not the other way around.
Next Steps
Once you've completed this checklist, compile your documentation into a collection summary. Include your data source map, hold notices and acknowledgments, collection logs, scope decision memos, and verification reports. Store this summary in your matter file where you can access it quickly if challenged.
If your collection process doesn't yet meet these requirements, start with the legal hold workflow. Build acknowledgment tracking and follow-up into your standard procedure. Then move to source mapping and chain of custody documentation. You don't need to fix everything at once, but you do need to fix the gaps before your next matter.
Defensible collection isn't about perfection. It's about being able to explain what you did, why you did it, and how you know it worked. If you can't answer those questions with documentation, your process isn't defensible yet.



