Skip to main content
Category: E-Discovery and Legal Holds

Preservation in Place

Also known as: In-Place Preservation, In-Place Data Preservation
Simply put

Preservation in place is the practice of securing and retaining data where it already lives, rather than moving or copying it to a separate location. It typically involves using technology to lock down the relevant data in its existing repository so it cannot be altered or deleted while it needs to be preserved.

Formal definition

Preservation in place refers to securing and retaining electronically stored information within the native repository where it is actively used, without relocating or duplicating it to a separate collection or archive environment. In the eDiscovery context it is commonly implemented as a technology-enabled control that locks targeted data in situ, and it is generally distinguished from custodian self-preservation, which relies on individuals to retain their own data. Because the data remains in its source system, this approach can preserve the full context of the material, including threads, reactions, edits, deletions, and associated metadata, which supports defensibility. Preservation in place should not be conflated with archiving, which involves moving data to a dedicated repository; the two serve different purposes and are often selected based on organizational needs and the requirements of a given matter.

Why it matters

Preservation in place addresses a recurring challenge in legal holds and eDiscovery: how to reliably retain potentially relevant electronically stored information without disturbing its original context or relying on individuals to safeguard their own data. When data is preserved where it already resides, the surrounding context can remain intact, including elements such as threads, reactions, edits, deletions, and associated metadata. Retaining this context is often important to defensibility, because it can help demonstrate that preserved material is authentic and has not been altered while under a preservation obligation.

The approach also offers an alternative to custodian self-preservation, in which individuals are asked to retain their own data. Custodian-driven approaches depend on human action and judgment, which can introduce gaps or inconsistencies. By using technology to lock targeted data in situ, organizations may reduce reliance on individual custodians and support a more consistent preservation posture. That said, the appropriate method typically depends on the organization's systems, policies, and the specific requirements of a given matter, and preservation obligations themselves vary by jurisdiction and sector.

A further consideration is the distinction between preservation in place and archiving. Because archiving involves moving data to a dedicated repository while preservation in place leaves data in its source system, the two serve different purposes and carry different implications. Treating them as interchangeable can lead to confusion about where data lives, how it is controlled, and how its integrity is maintained. Understanding this difference helps organizations select the method that fits their needs and the demands of the matter at hand.

Who it's relevant to

eDiscovery and litigation support teams
Teams responsible for managing legal holds and preserving potentially relevant material may use preservation in place to lock down data in its source system while a matter is active. Retaining the full context of the data, including metadata and evidence of edits or deletions, can support the defensibility of the preservation effort.
In-house legal and compliance functions
Legal teams weighing how to satisfy preservation obligations may consider preservation in place as an alternative to relying on custodians to retain their own data. Because preservation requirements vary by jurisdiction and sector, the suitability of this approach typically depends on the organization's systems, policies, and the specific demands of each matter.
Records and information governance professionals
Those responsible for how information is retained and controlled should understand the distinction between preservation in place, which leaves data in its source system, and archiving, which moves data to a dedicated repository. Recognizing that these serve different purposes helps ensure preservation methods are selected appropriately and not conflated.
IT and systems administrators
Administrators who manage the repositories where data actively resides may be involved in configuring the technology-enabled controls that lock targeted data in place. Their understanding of source system capabilities is often central to implementing this approach effectively.

Inside Preservation in Place

In-place retention
The practice of managing records within their originating system or repository rather than migrating or copying them into a dedicated records management system. The records remain where they were created or captured, and governance controls are applied to them in that location.
Overlay of recordkeeping controls
Retention rules, classification, disposition holds, and access controls that are applied to content in its native environment, typically through connectors, policies, or governance tooling that operate against the source system rather than by physical relocation of the content.
Preservation of record properties
The requirement that authenticity, reliability, integrity, and usability be maintained while the record stays in place. Because the content is not moved, safeguards against unauthorized alteration and against loss of context or metadata are typically needed to sustain these properties over time.
Metadata and context management
The capture and maintenance of metadata about the record and its relationship to the business activity it evidences, so that the record remains identifiable, interpretable, and defensible even though it resides in a general-purpose system rather than a records repository.
Disposition executed at source
The carrying out of lifecycle outcomes, which may include destruction, transfer, or continued retention, against the record in its original location. Disposition here is not synonymous with destruction, and preservation in place may support any of these outcomes depending on policy.
Scope boundary
Preservation in place is an approach to where and how records are governed; it is not itself a preservation-grade digital preservation program, and it may be less suitable for records requiring long-term permanent preservation, which often depend on more controlled environments.

Common questions

Answers to the questions practitioners most commonly ask about Preservation in Place.

Is preservation in place the same as simply leaving records where they are and doing nothing?
No. Preservation in place is an active management strategy, not passive neglect. While the records remain in their original system or repository rather than being migrated to a dedicated archive, the approach still requires deliberate controls to maintain authenticity, integrity, and usability over the required retention period. Depending on organizational policy, this may include applying retention and disposition rules, access controls, format monitoring, and audit measures within the source system. Leaving records unmanaged in their location of creation is not preservation in place; it typically increases risk to the record's reliability and defensibility.
Does preservation in place mean the records are permanently preserved and never need to be transferred or destroyed?
Not necessarily. Preservation in place describes where and how records are kept, not their ultimate disposition outcome. Records held in place remain subject to their applicable retention schedules and disposition decisions, which may include eventual transfer to another repository, permanent preservation, or authorized destruction, depending on the record's classification and jurisdictional requirements. Preservation in place is one method of meeting retention obligations during a record's life; it does not override or replace disposition planning.
When might preservation in place be an appropriate strategy for an organization?
Preservation in place is often considered when migrating records to a separate repository would be costly, technically risky, or likely to compromise context, metadata, or format integrity. It may suit systems that already provide adequate recordkeeping controls, or situations where the source application is expected to remain supported for the length of the retention period. The suitability of the approach typically depends on the system's ability to maintain the record's authenticity, reliability, integrity, and usability, as well as on organizational policy, risk tolerance, and any applicable regulatory expectations, which vary by jurisdiction and sector.
What controls should be in place to make preservation in place defensible?
To support defensibility, organizations generally seek to apply recordkeeping controls within the source system comparable to those a dedicated repository would provide. These often include reliable metadata capture, access and security controls, retention and disposition rule enforcement, audit trails or logging, and measures to detect and address format obsolescence or data loss. The specific controls appropriate for a given system depend on the record's value, risk profile, and any legal or regulatory requirements applicable in the relevant jurisdiction.
How does preservation in place affect the ability to apply legal holds and respond to discovery or access requests?
Because records remain in their originating system, the organization must be able to identify, locate, and suspend disposition of relevant records within that system when a legal hold applies. The system's search, retrieval, and hold capabilities are therefore important considerations. Where a system cannot reliably support these functions, preservation in place may complicate compliance with legal holds, discovery obligations, or access and freedom of information requests. The nature and scope of these obligations depend on jurisdiction and sector.
What are the main risks to consider before adopting preservation in place?
Key risks often include the potential loss of system support or vendor viability before the retention period ends, format or software obsolescence, inconsistent application of retention and disposition rules across disparate systems, and gaps in metadata or audit capability that could undermine a record's authenticity and reliability. There may also be added complexity in monitoring many systems rather than a single repository. Organizations typically weigh these risks against the cost and disruption of migration, and the assessment depends on the specific systems, records, and regulatory context involved.

Common misconceptions

Preservation in place means the records are simply left alone with no management applied.
The term refers to applying recordkeeping controls, such as retention, classification, holds, and access restrictions, to records in their native systems. It typically requires active governance rather than the absence of it; leaving content unmanaged is not preservation in place.
Preservation in place is the same as long-term digital preservation or archiving.
These are distinct. Preservation in place concerns governing records where they reside rather than moving them to a records system, whereas long-term preservation and archiving address sustaining records, often permanently, in controlled environments. Records requiring permanent preservation may be less well served by an in-place approach.
Because records are not moved, their authenticity and integrity are automatically preserved.
Keeping records in their original location does not by itself guarantee record properties. Authenticity, reliability, integrity, and usability typically need to be actively protected through controls against unauthorized change and through maintenance of metadata and context, since general-purpose systems may not enforce these safeguards on their own.

Best practices

Assess whether the source systems can reliably enforce retention, disposition, holds, and access controls before adopting an in-place approach, and identify records whose long-term or permanent preservation needs may require a different environment.
Apply and maintain the metadata and contextual links needed to keep records identifiable, interpretable, and defensible while they remain in their native systems.
Implement safeguards that protect authenticity and integrity in place, such as controls against unauthorized alteration and mechanisms to detect or prevent loss of essential record properties.
Ensure disposition can be executed at the source for all relevant outcomes, recognizing that disposition may include destruction, transfer, or continued retention rather than destruction alone.
Align retention and disposition rules with applicable requirements, noting that statutory retention periods, legal holds, and related obligations depend on jurisdiction and sector.
Establish periodic review of the in-place governance controls to confirm they remain effective as the underlying systems, policies, and business activities change over time.