December 21, 2010

Judge Richard A. Kramer comments on the California Electronic Discovery Act, one year later

by Cary J. Calderone


This blog covered the California Electronic Discovery Act (CEDA) when it was signed into law, more than a year ago. Now that a fair amount of time has passed, we may wonder whether it has helped, hurt, or had any effect at all on discovery proceedings and litigation in California state courts? To find the answer, I went to the Honorable Richard A. Kramer to ask his opinion.  Judge Kramer's department handles Complex Litigation for the Superior Court and he is nationally known for his rulings on same-sex marriage. However, I selected him for this piece because I had the pleasure of listening to Judge Kramer speak about electronic discovery and in particular, his practice of requiring litigants in his courtroom to agree to a “bring your geek to court day.” He is one of the most knowledgeable judges on the current issues surrounding electronic discovery and this makes him one of the very best sources for follow-up comments on the CEDA. After 3 weeks of pleasant, yet persistent pestering, the Judge was able to speak with me on Friday December 17. Here is the interview:

Calderone
: More than a year has passed since CEDA was enacted and signed into law. Have you noticed any changes? Can you say if attorneys and litigants are better or worst prepared to handle electronic discovery?
Judge Kramer: No difference. The attorneys who were familiar with the discovery of electronically stored information before, still are. And, those who did not understand it, still don't.
 

Calderone: Has the general understanding of what is necessary to comply improved?
Judge Kramer: The CEDA clarified a few concepts and some of the issues with electronic discovery. The law really did not change but those attorneys who were not very techno-savvy have now at least heard of the concepts and definitions. So perhaps there are fewer who look like a deer in the headlights when we discuss these matters in Court.

Calderone: Has anything with electronic discovery gone from bad to worse? Are there more disputes and accusations of inadequate production?
Judge Kramer: No difference under CEDA. The Court already had and has broad powers and discretion around discovery matters to protect the parties. If I could give one bit of advice to attorneys it would be, "if you don't know, fess up!" Do not make up unsubstantiated claims of cost or not being able to access the data.

Calderone: Can you comment on whether certain subject matters or types of litigation have had more or fewer issues with electronic discovery?
Judge Kramer: No difference.

Calderone: Where would you like to see continued improvement? Could the Act be clarified? Are lawyers still lacking in their understanding in some specific areas?
Judge Kramer: The CEDA is fine. It did not really change any law, just clarified some of the issues.

Calderone: Do you have any other particular hopes for the continued evolution of electronic discovery in litigation?
Judge Kramer: I would like to see attorneys subscribe to the Sedona Cooperation Proclamation, be more cooperative, and be more like a geek. A geek is the person who, when asked to fix your computer, he starts doing it. He is not always able to fix the problem completely, or, give you exactly what you ask, but the geek gets started and makes progress. Attorneys need to be more willing to indicate what they can do and can provide, instead of just claiming “it can't be done” or "it will cost a million dollars!" Eventually a smart geek on one side or the other will probably prove the attorney wrong.

In closing, let me express my great appreciation, respect, and gratitude to Judge Kramer for taking time from his busy schedule to speak with the DredLaw.com blog simply to help us better understand the CEDA and the state of electronic discovery in California today. In return, we hope that a few more of those attorneys and litigants who enter his, and other courtrooms in the state, will be a little better prepared for electronic discovery.

December 20, 2010

Breaking tradition-A review of my Asus Eee PC netbook, a great tool for the Cloud

by Cary J. Calderone

Over the past year and a half I have written about the move to the "Cloud" but covered primarily the Cloud providers and the move to hosted applications.  Now, as I sit typing away on my ASUS netbook, there is another reason to move my data skywards. This computer is so small, sometimes I have trouble finding it on my cluttered desk and I worry about leaving it behind at the coffee shop!  I would not feel safe carrying this around unless my data was stored someplace else, like the Cloud.  Let me disclose, I have no connection to ASUStek Computers, Inc. or ASUS.  I do not want to start reviewing hardware and software products or become the Walt Mossberg of the West. While many of you may not recognize the ASUS name, I know it to mean quality computer components. I used ASUS motherboards when configuring clone desktop computers in the 1990s but I have not been in that business since 1999.  Since an article I wrote in 1995 for Law Office Computing Magazine, I have not reviewed a hardware product.  So,why am I breaking with this tradition?  Because this netbook was inexpensive (under $400), surprisingly powerful, has an advertised 10.5 hours of battery life, and I love it!
 

Back when I reviewed the first “component laptop” with upgradeable features like RAM, micro-processor and hard drive, upgradeable meant it could serve you longer before becoming obsolete.  This could save you money. From today's perspective, 1995 was still the dark ages of laptop computing.  Think about a weapons dealer describing how effective his pointy stick would be back in 1995, and today describing the range of unmanned drones equipped with missiles. That is what the leap feels like between my review of a $2100.00, 386 20 Mhz Kiwi laptop then, (abstract of the article here) and this ASUS Eee 1005HA model equipped with an Intel Atom N280 1.66Ghz processor now. It also has a quiet 250G hdd, and the typical built-in networking and USB ports.
 
Pros
  • It has worked reliably for a year. Yes that is correct. I purchased this unit in December of 2009. So this is not the typical review one week after somebody gets their new electronic toy and is in the honeymoon phase. I used this netbook almost every day for the past year.
  • When I blog at a conference, the battery lasts me all day. I never have to worry about finding an outlet or resorting to paper and pen. I know I have used it on battery life for 8 hours before running low.
  • Unlike an iPad, I can use it like any full-sized laptop. It can sit on my lap, on a table, or, on the counter at the coffee shop. I felt I had the superior work tool while I typed on my Eee netbook while sitting next to someone whose iPad was teetering precariously on the multifunction cover/stand and would fall over frequently while he was reading it. My netbook stayed put!
  • Touch pad controls to scroll, zoom or shrink fonts and pages depending on your mood. (Think of shrinking or enlarging your view on an iPhone or iPad simply by moving two of your fingers closer or further apart) How do I know I like this feature? When I am on my full-sized laptop connected to my desk monitor, I find myself trying in vain to use this feature and it does not exist on my other computer. Fortunately it usually only takes a few seconds of trying before I realize this, and then I think fondly of my netbook.
  • The keyboard is large enough to type on. Some netbooks really make your fingers feel cramped.
  • Inexpensive and free offerings for cloud storage for your backup or data. Nice to have for those who have not yet tried other cloud options.
Cons-
  • Better video resolution would be nice but if it shortened the battery life too much, I am not sure I would like the trade-off. 
  • Tried video chatting and it worked, but was not even close to a typical desktop video chat experience. Will look to see how newer Eee models can improve this.
  • When it is not plugged in and is working in battery mode, it is noticeably slower. Once again, this has to be balanced against increased battery life.  
  • It took a while to get used to the touch pad features that I now love. When you have fairly large hands, you may have one or more pieces of your hand or thumbs accidentally touching the touch pad. So it is occasionally frustrating to be working and have an unexpected zoom or shrink of the page.
On balance, I had high hopes for this Eee PC, and they have been exceeded.  It proved to be a fantastic tool that helped me work more effectively and efficiently, in the Cloud.

December 17, 2010

What's that up in the Cloud? It's better infrastructure by EMC Atmos

by Cary J. Calderone

In a follow up to a few other posts on Cloud computing I am happy to report that EMC has been focusing on improving your Cloud experience. Their latest Atmos Cloud Delivery product line will enable Cloud providers to meter and provision Cloud usage. How does this help you in your DRED work?  As mentioned in my previous Cloud articles, Cloud providers, even the biggest names, have had a difficult time avoiding bottlenecks and slowdowns as Cloud usage grows. (What's that up in the Cloud?) They have not been able to adequately anticipate or control how and when some users will over-burden their equipment and cause a slowdown for all their Cloud users. If Atmos works as advertised, it will go a long way towards eliminating one of the biggest concerns companies face when considering a move to the Cloud; "will it work fast when we need it to work?"
Up until now, the Cloud providers have not been able to sufficiently monitor (and report) usage and data flow statistics. So they were faced with the very challenging task of trying to persuade a company to move to the Cloud while they could not actually show that availability and throughput would not be a recurring issue. Now with better monitoring and provisioning tools available, Cloud providers should be able to offer better availability and more reliability to their new and existing Cloud customers. Readers of this blog may ask, "who is EMC?"  Well, EMC is the largest providers of data storage technology and I would put in the category of a company like Cisco Systems. Even if you have not ever heard of them, if you use a phone or computer on the internet, then you use EMC products.  This is good news for the evolution of the Cloud.

November 19, 2010

Follow Up Conversation with Don Skupsky. The offer I couldn't refuse

by Cary J. Calderone, Esquire

After my last blog article, I wanted to follow up and share some of the items that I discussed with Donald Skupsky, JD, CRM, FAI, MIT, after his presentation.   It seemed like we had very different ideas on email management best-practices for organizations.  Just to be fair, open and up front, I shared my concerns with him and in typical fashion, once we had a more in depth discussion on the issues, it turns out we agreed on quite a bit.  For example, we agreed that most employees keep far too much email. 

The numbers he presented estimated that only 5% of email actually includes content substantial enough to be considered a Record.  I would add a few more percentage points for material related to Records. He also explained that there are some companies, a few, that do have a policy to tag and keep business record emails and have the rest deleted in 30-45 days, and they have been successful in defending their practices. They use a folder for Work-In-Progress but the main inbox gives the user a very short period of time to decide if an email is a Record, and then to move it to another location or repository for safekeeping, otherwise, it gets deleted.  There are a few companies that purport to use this policy, but I sure would like to see if they actually adhere to the policy in sufficient fashion to have it withstand legal scrutiny.

Mr. Skupsky also believes too many companies use a fall-back policy where they end up keeping pretty much everything, and this is a terrible practice.  I have witnessed this policy in action quite a few times. One company kept so much electronic information that when they needed to search its email archive, they were limited to 4 concurrent searches and it would take upwards of 12 days to get the first search results back. Not a very good system for Early Case Assessment or a Litigation Response team, to be sure.  So we both agree that when it comes to email, keeping everything, is a bad policy.

Ultimately Mr. Skupsky described himself as a bit of a devil's advocate.  By challenging a company with a 45 day email deletion policy, he believed it was more likely that ultimately, even if they would not agree to 45 days, they would agree to a relatively short deletion period of 6 months or a year.  He explained that if they were not challenged early, so they had to act to manage their email, users always defaulted to retention periods that are too conservative and too long or, they never take any action at all.  The end result would once again be email inboxes that are not managed.  His position is that if they are not going to manage it, then they are better off not keeping it.  So, while I cannot argue with Mr. Skupsky's goals, I will still persuade my readers to consider employing a different tact.  I prefer to suggest simple and straight-forward policies and guidelines that will help them eliminate upwards of 50% of their non-record and non-business related email quickly.  Too many users have stated that they would love to delete many emails but they were not sure if they could or should, so they kept them all.  Mr. Skupsky and I are both shooting for keeping less mismanaged information, but my method is likely to err on the side of keeping more business emails rather than fewer.  The lawyer in me wants you to keep information that may help us understand your case.  Is it a perfect system?  No.  But making users affirmatively move Records, to safeguard them from deletion seems riskier.  After the first 50% is removed from the inbox, we can then work on managing the next 30-45%, which will likely be more challenging, but can be better managed with some department and function-specific policies and procedures, and perhaps some of the great new search and management tools that are available.  Either system correctly employed and monitored will reduce a great deal of email clutter.  And, this, in and of itself, will provide a huge cost-savings for the over-stressed IT department.  It will also enhance any Litigation Response program that needs to address eDiscovery.  I just want to be more comfortable that the Litigation Response team will find relevant information on their own servers, before they see it produced by an adverse party in litigation!

My approach comes from the basic belief that the use of technology is critical to an organization's success and they must keep up with new productivity features to stay competitive.  So, I want to allow for expanded usage, and less effort to manage that usage.  Mr. Skupsky believes records retention practice actually can help support the use of technology too.  He just abhors mismanaged data growth.  So while on the surface we agree, I lean toward recommending any Retention and Records and Information Management policy will be flexible enough to be updated, and amended to reflect the ever-changing needs of the users.  And, whenever possible, allowing the users more use of the data and any new technology enhancements.  The new reality is many companies are now contracting and performing other substantial business functions via email, electronic exchanges, and even Social Networking sites.  So if the RIM program is too limiting on the use and retention of electronic data, it runs the risk it will become impossible for employees to follow it thereby making it irrelevant. The days of following simple static rules that worked fine for slow moving paper are gone.  It is time to keep up with email, Facebook, Twitter, and whatever may come next.

Special thanks to Donald Skupsky, for taking the time to consider and respond to my comments.  

November 11, 2010

ARMA Session-Retention for Electronic Records-Or, Don Skupsky, some of your tips should sleep with the fishes

by Cary J. Calderone, Esquire

Donald S. Skupsky, JD, CRM, FAI, MIT is certainly one of the most respected and recognized Records Management thought leaders.  If he is not the Godfather of Records Management, he is certainly a Godfather.  His book/treatise is still the foundation for many corporate Record Information Management programs.  However, coming from my background as a lawyer and IT consultant, (see blog post "Who are you talking to?") some of the RIM ideas he presented in this talk are really not applicable in the 21st century world of managing electronic data.  Case in point, he suggested companies have a policy to delete email after only 30-45 days?  Whoa!  This is really not a "best practice" for most companies.   Let me explain.  

When I started helping companies update their RIM programs and become DRED ready, I found some challenges with the old guard Records Managers who cut their teeth, and perhaps their fingers, on paper. The drill was, declare a Record, protect it for the retention period and shred the other convenience copies.  Simple.  As readers of this blog already know, there are many reasons why this approach no longer works for email and other fast-moving electronic forms of communication.  (see Shout out to Records Managers)

While Mr. Skupsky has expanded on his original definition of what is a "Record" to allow companies to define it to include various electronic forms, at other times during his presentation, he seems to completely forget the main reasons companies have and use technology.  For example, let's consider his suggestion of as little as a 30 day retention period for email.  Under his 30 day policy, users are supposed to take any email that qualifies as a "Record," (defined by the company policy) and move it to another document management system or, print it out for safekeeping and storage.  Even if your company does not already have a specific legal requirement (like SEC 17 a-4, or Sarbanes-Oxley) to retain email communications, there is a very good chance employees who use their email as a work productivity tool have a habit of keeping them for later reference for at least a year or two, if not forever.  Can you imagine how many people would not bother complying with the rule if it meant moving only select "Record" emails to another system or printing them out for safekeeping? 

In today's world, employees are using search technology, like Google Desktop and other search engines and crawlers, to mine their own electronically stored information for answers.  It is a basic form of Knowledge Management and in many cases, a major productivity enhancement.  So, if you have a 30 day deletion rule, and nobody wants to follow it, chances are, they won't.  Which means you will end up with a policy that ultimately shows at least one part of your RIM program is a sham.  Not a good move if you end up in litigation someday.  

Moreover, even if the 30 day policy is supported enough to pass a test in a discovery dispute in court, it is still not advisable.  What about your early case assessment needs?  Email that might be critical to determine if a potential matter has merit, may be deleted from your servers, but it will likely still be in the possession of your potential adversaries.  Or, perhaps it was printed out, or kept in another management program.  How many hours will it take to retrieve and review those stored emails?

Even assuming your employees are willing to perform all the extra work to print and/or move those potentially critical emails, some of them may have content that would show that your employee(s) made a mistake.  How much effort will your employee(s) expend to store, search and retrieve those darn emails that may show they should be terminated?  I would bet that at least a few employees might just let those pesky emails get deleted after 30 days and hope for the best.  Once again, the result is potential discovery trouble for your company.

While I appreciated much of the presentation, it was a little bothersome to hear Mr. Skupsky's dismissive description of "groupware tools" which he "does not like."  In the tech industry these might be separate development applications or wikis or even Instant Message comment threads.  Does Mr. Skupsky believe that all of these amazing advances in the area of software and collaborative development will just go away because they are difficult to track and maintain according to a simple Records Retention Schedule???   I am betting the answer is a resounding "No."  These will be distributed and used and even more tools will be invented.  And, realistically, this will be so even if these tools make records management, more challenging.  Facebook, Twitter, and Cloud applications, may make managing records more difficult, but they are not going away.  We have to learn to proactively manage them.

I understand and respect the established industry protocols and efforts of any company in maintaining a working RIM program, but without a better understanding of how and why the new technologies are employed, creating "dream world" easy-to-manage electronic records policy, is not ultimately going to be productive, and may cause very serious issues in an otherwise well-intentioned RIM program. 

I could not argue against some of his ideas without giving Mr. Skupsky a chance to explain himself, so I spoke with him after the session.  The next blog post will cover our discussion.   

November 10, 2010

ARMA Show-A couple of useful new products and upgrades for your DRED project

by Cary J. Calderone, Esquire

Here are a few interesting product offerings I noticed at the ARMA Show this week.  This is not a product review.   I have not tested the products but just looked at their demonstration modules.   However, I like to point out when I find a product that can and will fix specific challenges for many companies.  The two products I noticed come from,  Page Freezer, and ZL Technologies Inc.


Page Freezer  simplifies the task of maintaining and tracking copies of your website and other online representations and communications.  In my experience I have found many organizations need or want to keep copies of their website information and twitter feeds.  These may include representations of service or product features and sometimes they must be tracked in order to comply with a Public Information request or Legal Hold.  Either way, it is difficult to keep and track a website that may be updated daily by many different departments and authors.  Who is responsible to archive all the changes?  Page Freezer can automatically archive selected pages or entire websites on the fly according to the rules you setup. The product also tracks Twitter updates and supposedly will be able to archive Facebook updates as well.  I know quite a few organizations that would like to be using this tool right now.
ZL Technologies Inc. has added new features that allow its customers to "manage in place."  Many companies operate internationally, and are faced with very challenging and frequently conflicting laws concerning email communications and electronic data storage and retention management.  ZL technologies has added features that will allow its users to archive and manage electronic data in place, even in a location like Japan.  There are many solutions that can managing data in the US, especially when it is all in English.  But when information is collected from many places and in many languages, there are extra challenges to the solution, and there may even be prohibitions against moving some types of data, i.e., across country borders.  In these instances, managing in place can be a most useful feature.   Many companies have tried to move all the electronic data to one central  location, to be managed according to one set of rules.  Not only does this mean potential bandwidth and regulatory problems, but how many people in your main U.S. office can read and manage information that is in Japanese or some other language?  Usually, the answer is nobody.  So you have moved the data away from the very people who are most capable of managing it because they can read it and know the local rules that apply to it.  ZL Technologies is trying to give you, a better way.     

November 3, 2010

Computer Forensics Show

by Cary J. Calderone, Esquire


I was able to spend limited time at The Computer Forensics Show in San Francisco this week. I understand when a show is debuting in a new city it may have issues, but the acoustics at the Herbst Pavilion at Fort Mason were pretty awful and, I am not the only one who noticed. It's too bad because the show did have some very good speakers and covered interesting DRED topics. Still, it was challenging to enjoy their presentations due to the acoustics.  Background noise notwithstanding, here are a few highlights:

Dean Gonsowski, Vice President, e-Discovery Services at Clearwell Systems, presented "Compliance in the Cloud and the Implications on eDiscovery. He provided a very nice overview of many issues that need to be considered when looking for a solution in the Cloud. Even when I asked about a tricky issue, i.e., "what to do when your data may be co-located across international borders?", he provided a thoughtful and practical approach. He had other terrific "checklists" to use when you look at Cloud solutions, but I am not listing them here. You'll have to see one of his presentations yourself.

I also enjoyed the session run by Michael Glick, Vice President of Encore Discovery Solutions "How Advances in Modern Electronic Discovery Practice are Changing Commonly Held Notions About Conflicts of Interest." He described the advantages to litigants following the Sedona Conference Cooperation Proclamation and waiving some potential conflict issues, and cooperating with adversaries during electronic discovery. There area even times when using a single provider and platform can save everybody money and hassles. I asked if Encore had protocols conflict checks for their eDiscovery clients? Much like lawyers and law firms, Encore follows high standards and protocols to ensure they do not represent parties with adverse interests. Pre-engagement conflict checking is too often an afterthought with some consulting groups in the DRED space and it shouldn't be.

On balance, I hope that this conference grows, finds a better location, and returns to San Francisco next year. If they continue with legal tracks that include good DRED discussions, I will attend again.

October 28, 2010

Attending the Computer Forensics Show

by Cary J. Calderone, Esquire
 
I will be checking out The Computer Forensics Show Nov 1 and 2 at the Fort Mason Center right here in San Francisco. (You know San Francisco, where the Giants play World Series baseball...) It is my first time attending this particular event but I expect it to be worthwhile. As my readers know, there is a very important relationship between DRED and computer forensics, so I will observe the legal tracks and hopefully learn more about when and what specific factors trigger forensic investigation, and how forensic tools may be used proactively, to avoid pain and greater costs later. 

Given some of the panel discussions they have scheduled, I am sure I will find some "blog-worthy" material.

October 26, 2010

Who are you talking to? You talking to me?

by Cary J. Calderone, Esquire

Here comes a little rant.  I try to be nice, really I do.  But it is very frustrating when my energy and efforts to help a client are thwarted or, challenged by more aggressive and "less informed" consultants and sales representatives posing as consultants.  Attorneys, sales reps and consultants usually have different education backgrounds, different experiences, and different motivations.  So I wanted to devote this blog post to summarize and distinguish these three professionals who may be employed to assist you with your DRED project. 

First, there is the sales representative who makes some or all of their salary by making a sale.  They have to get you to say "yes" to their product or service in order to earn their commission.  Accordingly, they are not the most motivated when it comes to telling you how their product might fail you or how over-simplified their "form data retention policy" might be.  Most seasoned customers recognize the motivation of the nice and helpful sales rep and view their information as potentially inaccurate. 

Next there is the consultant, (and not one that is really tied to a specific product which makes them a sales rep disguised as a consultant) offering you "best practices." The consultant needs to make you happy with the service and/or product they select so getting you to say "yes," is not always enough.  If it doesn't work out as advertised, you probably will not want to pay for it.  So, where a sales rep might proclaim a product definitely can handle your needs, the experienced consultant will hedge a bit, to avoid possible fallout later on.  I get quite a few questions from "consultants" asking me to explain some point of law to them so they can explain it to their client. I typically do not help them.  It is their intention to take complex legal points and simplify them because, "that is what their clients like." Needless to say, simple is not accurate and frequently will cause their client more harm than good.  A little information truly can be a dangerous thing.

Lastly, there is the attorney (cue dramatic background music).  The attorney is risk-adverse and picky about simple statements of the law.  We learn that words have meaning and appreciate that even when sales reps and consultants use our words or case law appropriately, they often find a way to mess up the scope or analysis of the legal principle. While attorneys are often derided for making the simple seem complex, in our defense,  frequently things that appear simple, are simply not.  And, when it comes to your legal obigations, we attorneys are the ultimate and best source to evaluate your legal hold, data retention and eDiscovery policies and procedures.  Most good sales reps and consultants agree with this.  even if they occasionally forget it while they try to "help" their client.

So, who are you talking to?   When it comes to legal points, I hope it is your very wise and well-informed attorney. Can you hear me now?

October 18, 2010

ARMA International Conference and Expo in San Francisco November 7-10

The ARMA (Association of Records Managers and Administrators) Show is coming to San Francisco November 7-10 and should be excellent.  Although I was not able to attend the show in Orlando last year, I attended the Las Vegas Show in 2008 and found the panel discussions and presentation to be very worthwhile.  The highlight for me is that the speakers are often practitioners with a gift for educational presentations, and not just sales gurus and product marketers. 

The guidelines for ARMA prohibit speakers from simply selling their services.  The end result is that they offer more "real-world" examples of tackling and succeeding with Records Management, Litigation Preparedness and e-Discovery projects.  I have participated in local ARMA chapter events in Silicon Valley, San Francisco and Contra Costa County but will just blog about this event.  The local and national organizations are a great resource for anyone interested in learning more about Records and Information Management, or DRED.  For more information you may go to their website www.arma.org.   See you at the show.

September 28, 2010

Virtual LegalTech- Neat technology but where are my t-shirts and snacks?

Last week I checked out Virtual LegalTech for the second time this year.  In brief, it employed very cool technology and some of the presentations used streaming video and the new technology very effectively.  Others, not so much.  On the bright side, a boring Powerpoint presentation can be put in a smaller window to the side and I can surf the web while the boring speaker drones on.  In person at typical conferences, escaping a boring presentation can be much more challenging.  While some features of a "virtual conference" mirror the real world experience, others are missing.  

If you loiter near a booth, or, even walk by a little to slowly, at a conference, a sales representative will jump out at you, scan your data to get you on an email list, and then strike up a conversation or try to show you their demo and maybe get you on a path towards a sale.  At Virtual LegalTech, you are only bothered by the occasional pop-out chat window asking if they can answer any questions.   Less bothersome to be sure and not a bad way to type hello to a few people you may already know.  And, they already have your name and email.  Do I believe this technology will replace live, in-person conferences?  No.  Business people will always need excuses to network and showcase their wares and trade shows are still the superior showcase.  However, I do believe this technology will reduce the frequency of the live events and perhaps dramatically so.  During the past two years during this dismal economy, everyone involved has noticed an overall decline in attendance.   Virtual conferences have to be significantly more cost effective and that alone will make them an alternative, or an add-on to marketing budgets.  I did hear some excellent presentations and received Continuing Legal Education credits for some of them.  But it is still kind of sad that I attended two of these Virtual LegalTechs and didn't get a candy bar, snack, toy, or even one single t-shirt as a memento.  Maybe as the technology improves...

September 27, 2010

Do you Tweet? Are you on Facebook? You need a policy!

Some companies have really benefited by using Twitter and Facebook accounts to grow and cultivate their customer base.  And many other companies are taking notice and making plans to do the same.  But, there are some very important precautions you should be taking before you ask your clients and friends to "Like" you online.  Do you have a policy or retention schedule that covers your social media interactions?  If not, you need one.  This type of communication is potentially "relevant" material to any matter dealing with customer representations and advertising.  Depending on your industry, you may be specifically required to manage and retain this information or, your lawyer might just suggest it as a good idea.   I know there are more lawyers who are learning about this new area of business communication, but there are still too few.  Please find one who understands it and speak with them, or, contact us so we can help. 

May 18, 2010

IQPC eDiscovery Panel-Protecting Privileged Communication

by Cary J. Calderone, Esquire

Moderator, Mark Michels, Managing Attorney, Cisco Systems, Inc.
Craig Carpenter, Vice President and General Counsel, Recommind, Inc.
Martin T. Tulley, Partner and E-Discovery Practice Chair, Katten, Muchin, Rosenman, LLP

This panel was focused on Federal Rule of Evidence (FRE) 502 which governs attorney-client privilege and work product; limitations on waiver.  502 was drafted specifically to cover electronic discovery and inadvertent disclosures.  I have had the pleasure of listening to Mark Michels at other presentations and, as an audience member, I always appreciate that he tries to make his panel discussions interesting, lively, and a little bit fun.   After sitting in on 5 or 6 eDiscovery sessions over the two days at the IQPC eDiscovery conference, I believe anybody sitting in this audience appreciated that he made the panel discussion entertaining, as well as informative.

The first hot topic was protective orders with claw-back provisions. The panel was interested in whether people had ever had a "quick peak" (i.e., noticed that your opposition sent you privileged information and had to report it to them) and made the following points:

  • Mistakes will happen.  We are dealing with an enormous volume of data.  There is fear of privilege waiver but there is also significant cost in taking precautions. 
  • FRE 502- Now with 2 years of precedent it is better understood.
  • 502(d) limits waivers of attorney/client privilege, promotes certainty and reduces litigation risks.
  • 502(e) indicates that a Protective Order is still prudent.
  • There is a big presumption against broad subject waiver.
Mark asked, "when is a disclosure not a waiver of privilege?"
Martin provided a checklist of factors:

  • Privilege?-Was it privileged to begin with?
  • Inadvertent?-Was the disclosure inadvertent?  Some courts not-intentional equals inadvertent. Other courts have a checklist of factors to consider.
  • Reasonable?-Advisory committee notes to 502 do not define it.  Rather, the Committee notes list factors to consider such as precautions and steps taken after disclosure to attempt to rectify?
  • Extent of the disclosure?-Overriding issues of fairness.  Was there a defensible Records Management program?  For example, was it 4 out of 10,000 documents?  Did the disclosing party take quick action?  Court found it reasonable and therefore there was no waiver of the privilege.  
  • Best practice-Always have a protective order with a claw-back provision.
  • Waivers have been found where the producing party could not describe what they did...so document your procedures.
  • Perfection is not expected.
It was pointed out that whether FRE 502 would be binding in state courts, has not been tested.
Citing the Victor Stanley case and Judge Grimm be prepared to answer, "did you do enough to find the privileged documents?"
   
The panel also mentioned the Amobi v. District of Columbia case where Judge Facciola discussed "inadvertent."  The Judge's analogy was paraphrased; "while 502b would allow me to round up the animals and put them back in the barn, were reasonable steps taken to avoid letting the animals out?"
One of the precedents was clear.  When the data had been produced to the expert witness for review, privilege was waived.

The panel then examined what would be considered "reasonable" efforts to find and protect your privileged information.  Keyword search alone is usually not sufficient as it finds only 25% of documents, so you should add in sampling.  The type of vendor you are working with can make a difference.  Do they understand the methodology and work flows around it.

Craig Carpenter provided an extensive list of search features that could help.  He mentioned threading, email de-duping, visualization (being able to see who spoke with whom and when on certain topics), concept search (relate documents that are substantively similar but may not share keywords), clustering-(particular set of keywords-take first few documents that relate to the category), grouping-(more sophisticated clustering-take all documents that relate to the category) automatic categorization (the tool does it for you), amd predictive coding (form of automated review). 
Not surprisingly, Recommind's impressive products are capable of helping you with all of these search techniques.   Craig was in "teaching mode" and not in sales mode and his examples and explanations were excellent.


The panel discussed an instance of dealing with 2.5 million documents and the client did not want to pay for privilege review but rather, instructed outside counsel not to turn over anything privileged. LOL!  Obviously it would cost too much.   So, with client's consent, they used automated review tools with some direction from knowledgeable people.  They were able to save 3 or 4 months of processing time and several million dollars.

Mark Michels said "hypothetically," what if he was the "impecunious client?"  "How could they be reasonable and save money too?"  The panel proposed technology search with Bayesian models and sample seed sets to help cull down the data but then made it clear that "at some point, you have to put some eyes on it."  100% automated tools or 100% manual and people-powered processes have not been favored by the courts.

The last "best practice" was to re-iterate that it was critical to define "reasonableness" or, through agreement with the other party(s), take "reasonableness" out of the equation by agreeing what both parties would do for production and what would happen in the event of any inadvertent disclosure.  They closed with one of the best lessons for those who would rely solely on FRE 502 to save you from waiving privilege during disclosure:  Crediting Judge Grimm for the analogy, 502 was "like a bungee cord.  It can save you, but it is still a terrifying experience."


May 17, 2010

IQPC eDiscovery Panel-Global Issues

by Cary J. Calderone, Esquire

David C. Shonka, Esquire-Principal Deputy General Counsel, Federal Trade Commission
Benton Armstrong - Principal, Analytic and Forensic Technology, Deloitte Financial Advisory Services LLP

David Shonka stressed from the beginning, "if there is one takeaway best practice from this session-get local advice.  European Union directives are not the last bit of advice.  Each nation has its own interpretation of it.  Local law firms in Europe and Asia are much more sophisticated now and can offer better advice."

Initial considerations for global eDiscovery:

  • Who has Jurisdiction?
  • Who has control of the data?(maybe a 3rd party?) (Where is that party sitting?)
  • Duplicate copies in the US?
  • Where does the data sit?
  • If you can get it, can you move it?  Lot of restrictions on transfer (personal and sensitive data)
(Source-Sedona Conference Framework for Analysis of Cross-Border Discovery Conflicts August 2008)

Companies are employing new mobile technologies to go in with a small data center to process out personal and private data, then you can negotiate for collection/transfer from that point.  For example, data sitting on server in Eastern Europe but it is Austrian employees' data.  It was treated as though they were doing a collection in the Czech Republic.  They ultimately collected what they needed but it was a very long and difficult process-got consent from the Data Privacy officer in the Czech Republic.  Since this is a relatively new phenomenon, they are being extra cautious. Multinational organizations need to anticipate this.

There can be problems when parties do not want to cooperate but ultimately they do.  Preservation process- while the consent process is going on the data is not preserved.  Employees delay and then 5000 deletions will occur just before the data is supposed to be preserved.

We are getting better and more sensitive to private data in the US but still not equal to the EU.  Convergence going on-don't think they will ever meet-but the realities of dealing with a global economy is forcing people to cooperate.  Reminder that under the EU directive, looking at data equals "processing" and there are different stages:

  • Retention
  • Disclosure 
  • Onward transfer 
  • Secondary use
There are also international collection considerations such as:

  • Who collects?  Employees?  Can cause problems
  • In what form?  Native or a forensic copy? Physical or logical?  Remote or direct connect?

Best practice from Benton Armstrong-"get all stakeholders together at the outset."Records Managers, Legal, IT from many if not all different offices and locations. Get the potential roadblocks out in the open early so you can plan for some of them. It will make the process much faster.

One positive thing I learned from this panel is that, since I first started this blog, the best practices for international eDiscovery have evolved. While certainly not simple and without potential pitfalls, there are now better operating procedures and protocols for negotiating this tricky area. I suspect as more and more global companies implement policies and procedures and have better trained and more experienced practitioners involved, the potential pitfalls will continue to dissipate.

IQPC eDiscovery Panel-Roles of In-House Counsel and Outside Counsel

Vincent Miraglia, Chief Counsel - Employment Litigation & Electronic Discovery International Paper
Vickie Lee Clewes, Senior Manager, Commercial Legal Affairs, Gilead Sciences, Inc.
Moderator, Wayne C. Matus, Partner Pillsbury Law Firm

Wayne Matus started the discussion rolling by asking the panel, "What keeps you up at night?"
There were two answers:
  1. For things like government subpoenas and investigations, it is very hard to have processes already in place, so managing the discovery is very challenging. 
  2. For inside counsel, it is very difficult to manage many legal holds and keep mindful of when they "anticipate" new litigation. 

The panel noted it was difficult to have a cohesive company-wide plan. They still had to address the individuality of each office/department while balancing the tie between discovery and risk.

Vinnie thought that "less is more" and that he does not want all of the data, just the relevant stuff.
He gave an example of PST files.  They had established a delete policy (60 or 90 days) and used legal hold and archiving tools to move and archive necessary email. 

They referred to the Zubulake case (6) and explained that since "terminating employees" could lead to litigation, a best practice would be to freeze all data for terminations for a set period of time.


Question from Wayne-What about the fact that they may get hit with a lawsuit in a new area?   The panel believes in meeting and discussing potential new stuff often with outside counsel.  They also found that, almost always, outside counsel is conservative about when legal holds are necessary. 


What keeps Wayne up is the eDiscovery process maps he creates with his clients do not say all decisions should be documented.  For example, "this is why I did or did not issue a legal hold."

Vicki thinks they do need to document more.  Since we are shooting for "reasonableness" better to show what you considered at the time.


Question from Wayne-How important is communication between inside and outside counsel?
Vinnie's response-Keep it like a working partnership so Vinnie may respond to some discovery requests and outside counsel may respond to others.  He thought that the legal bills go down with better communication.