Every legal operations professional has received the email: "We collected the files ourselves and uploaded everything to the shared drive." What follows is rarely good. Missing metadata, incomplete search terms, and overlooked relevant sources are common issues when clients handle their own eDiscovery collection.
According to Nextpoint's 2026 eDiscovery Landscape Survey, 31% of respondents cited working with clients to collect data as a firm-level challenge. The problem isn't technical infrastructure or review platform limitations. It's a communication breakdown where legal requirements meet client understanding.
This checklist provides a defensible framework for managing client data collection. Use it to structure your intake process, document your collection scope, and know when client self-collection crosses from efficiency into risk.
Prerequisites
Before you begin any client collection process, confirm:
- Matter intake is complete. You have a signed engagement letter and documented preservation obligations.
- You understand the client's data environment. You know whether they have IT staff, existing information governance policies, or records retention schedules.
- You've identified key custodians. You have names, roles, and preliminary data source information for individuals likely to hold relevant information.
- The client understands why collection matters. They grasp that this isn't administrative busywork but a legal requirement with consequences for incomplete or altered data.
Collection Planning Checklist
1. Document the scope conversation at matter intake.
☐ Explain what collection involves: types of data, expected timeline, and how information will be secured.
☐ Clarify why completeness matters: spoliation risk, adverse inference instructions, and the cost of re-collection.
☐ Identify whether the client has existing data governance policies or IT support that will affect collection logistics.
☐ Record this conversation in your matter file with date, participants, and key points discussed.
Good looks like: A dated memo or intake form showing you explained the collection process before requesting documents, creating a defensible record of reasonable notice.
2. Deploy a structured pre-collection questionnaire.
☐ Cover all standard sources: corporate email, file servers, cloud storage (Google Drive, Dropbox, OneDrive), mobile devices, collaboration platforms (Slack, Teams), and third-party systems.
☐ Ask about personal accounts used for work purposes (personal email forwarding, personal device usage).
☐ Include questions about document retention practices and any automated deletion policies.
☐ Require written responses, not verbal summaries.
Good looks like: A completed questionnaire that surfaces non-obvious sources (the project Slack workspace, the vendor portal, the archived email account from a predecessor) before you finalize your collection plan.
3. Conduct custodian interviews to validate questionnaire responses.
☐ Schedule individual conversations with each key custodian, not group meetings where people defer to each other.
☐ Walk through their daily workflow: How do they communicate? Where do they save drafts? What tools do they use that aren't on the company's official list?
☐ Probe inconsistencies between questionnaire answers and interview responses.
☐ Document each interview with notes that capture specific systems, habits, and any sources the custodian initially forgot.
Good looks like: Interview notes that reveal the Gmail account a custodian used to email documents home, or the Box folder a consultant set up outside the corporate system, giving you collection targets you wouldn't have found from the questionnaire alone.
4. Define clear boundaries for client self-collection.
☐ Decide which data sources the client can handle (low-risk, well-understood systems) and which require attorney oversight (complex databases, systems with metadata concerns).
☐ Provide written instructions covering scope, date ranges, search terms, file types, and the requirement to preserve metadata.
☐ Specify the format for delivery: native files, not PDFs; Business Classification Scheme intact; no selective editing.
☐ Set a deadline and require confirmation when collection is complete.
Good looks like: A one-page instruction sheet that tells the client's IT team exactly what to collect, in what format, by what date, with explicit warnings about metadata preservation and scope completeness.
5. Monitor self-collection closely and verify results.
☐ Request a preliminary file list or sample before full collection to confirm the client understood your instructions.
☐ Check for metadata integrity: creation dates, modification dates, author information.
☐ Compare collected volume against expected scope (if you asked for three years of email from five custodians and received 47 files, something's wrong).
☐ Follow up immediately on gaps, anomalies, or format problems.
Good looks like: A verification log showing you spot-checked metadata, confirmed date ranges, and identified missing sources within 48 hours of receiving the client's upload, not three weeks later during review.
6. Address data security and privacy concerns before they become obstacles.
☐ Explain your firm's data handling protocols: encryption in transit, access controls, retention limits.
☐ Describe the security posture of any third-party platforms (your eDiscovery vendor, cloud storage, review tool).
☐ Clarify who will have access to collected data and under what confidentiality protections.
☐ Document these assurances in writing so the client has a reference.
Good looks like: A data security FAQ or one-pager you can send to clients at intake, preempting the "we're not comfortable uploading this" conversation that stalls collection for two weeks.
7. Create a collection completion record.
☐ Document all sources searched, including those that returned no results.
☐ Note any sources identified but not collected, with explanation (outside date range, custodian departed before relevant period, etc.).
☐ Record search terms, date ranges, and custodians for each data source.
☐ Have the client or their IT representative sign off that collection is complete to their knowledge.
Good looks like: A collection summary you can attach to a discovery response or produce in a sanctions hearing, showing you made systematic, documented efforts to identify and collect all relevant sources.
Common Mistakes
Assuming the client knows what "relevant documents" means. They don't. Clients think in terms of final versions and formal correspondence. They don't instinctively include drafts, internal chats, or the spreadsheet they built to analyze the decision you're now litigating.
Delegating collection without verifying results. If the client's IT person misunderstands your scope or applies the wrong date range, you won't discover the problem until opposing counsel points out the gap in your production.
Skipping custodian interviews to save time. The questionnaire alone won't catch the personal email account, the retired laptop in someone's closet, or the collaboration tool that only three people on the team used. Those gaps become spoliation allegations.
Treating data security as an afterthought. Clients who don't trust your data handling will drag out collection, produce incomplete information, or push back on scope. Address security upfront and you eliminate that friction.
Next Steps
Once collection is complete and verified:
- Log all collected sources in your matter management system with custodian, date range, and file count.
- Preserve the native files in a secure repository before processing or review.
- Update your legal hold notices to reflect collected sources and confirm ongoing preservation obligations for uncollected systems.
- Conduct a collection debrief with your team to document lessons learned and refine your process for the next matter.
Client collection isn't a one-time document request. It's a structured process that requires clear communication, systematic verification, and documented decision-making at every step. The fifteen minutes you spend explaining the process at intake will save you hours of re-collection, and possibly sanctions, later.



