May 17, 2010

IQPC eDiscovery Panel-Roles of In-House Counsel and Outside Counsel

Vincent Miraglia, Chief Counsel - Employment Litigation & Electronic Discovery International Paper
Vickie Lee Clewes, Senior Manager, Commercial Legal Affairs, Gilead Sciences, Inc.
Moderator, Wayne C. Matus, Partner Pillsbury Law Firm

Wayne Matus started the discussion rolling by asking the panel, "What keeps you up at night?"
There were two answers:
  1. For things like government subpoenas and investigations, it is very hard to have processes already in place, so managing the discovery is very challenging. 
  2. For inside counsel, it is very difficult to manage many legal holds and keep mindful of when they "anticipate" new litigation. 

The panel noted it was difficult to have a cohesive company-wide plan. They still had to address the individuality of each office/department while balancing the tie between discovery and risk.

Vinnie thought that "less is more" and that he does not want all of the data, just the relevant stuff.
He gave an example of PST files.  They had established a delete policy (60 or 90 days) and used legal hold and archiving tools to move and archive necessary email. 

They referred to the Zubulake case (6) and explained that since "terminating employees" could lead to litigation, a best practice would be to freeze all data for terminations for a set period of time.


Question from Wayne-What about the fact that they may get hit with a lawsuit in a new area?   The panel believes in meeting and discussing potential new stuff often with outside counsel.  They also found that, almost always, outside counsel is conservative about when legal holds are necessary. 


What keeps Wayne up is the eDiscovery process maps he creates with his clients do not say all decisions should be documented.  For example, "this is why I did or did not issue a legal hold."

Vicki thinks they do need to document more.  Since we are shooting for "reasonableness" better to show what you considered at the time.


Question from Wayne-How important is communication between inside and outside counsel?
Vinnie's response-Keep it like a working partnership so Vinnie may respond to some discovery requests and outside counsel may respond to others.  He thought that the legal bills go down with better communication.

May 6, 2010

IQPC Judges Panel on eDiscovery

by Cary J. Calderone, Esquire



Readers of this blog know that I am always happy when we have the opportunity to learn about DRED issues directly from judges.  I had the privilege of attending the Judges Panel on eDiscovery at the IQPC eDiscovery Conference in San Francisco.  This was a very worthwhile session and attendees learned some great insights about the "Real World" of eDiscovery that occurs in actual court cases.  And, by actual court cases, I mean the majority of cases you will probably never read about because they do not involve extreme examples of eDiscovery misconduct and multi-million dollar sanctions.  Hopefully, these are the cases that your legal matter will most closely resemble.  Moderated by Craig Carpenter, V.P. and General Counsel, Recommind, Inc., U.S. Magistrate Judge Robert B. Collings, District of Massachusetts, and U.S. Magistrate Judge Elizabeth D. Laporte, Northern District of California, provided updates to the law.  I am happy to report that in the 3-plus years since I have been working almost exclusively with eDiscovery issues, there has been evolution and progress, and there are now better guidelines to help keep your business or department DRED-ready.


Some of Judge Collings recommendations included:

  • Reading the article by Judge Facciola-Federal Courts Law Review on privilege review   
  • Urging counsel get a court order with respect to a Section 502 waiver
  • Whittle eDiscovery down the the issues you have actually have in dispute
  • As an Observer to the Sedona Judicial Working Group-Courts are looking for more cooperation between counsel and less adversarial posturing during the Meet and Confer process
  • Parties need to be more transparent about what, how, and where their data is located
  • Don't take expensive 30(b)6 depositions unless necessary
  • Bring your IT experts to the Meet and Confers
  • A reasonable proposal and approach will get the Judge's support
  • Settling cases for purely economic reasons has always occurred -eDiscovery is exacerbating this
Judge Laporte also provided some important insights:

  • There is a wide range of parties and sophistication-She has given attorneys eDiscovery homework
  • Lawyers who typically do not deal with eDiscovery now have to learn it
  • Client is responsible for getting it right-Courts look to see who is really engaged in the wrong-doing (citing Qualcomm case where the court found no bad faith on the part of outside counsel)
  • Standard is what is reasonable at the time
  • If you agree with opposing counsel as to procedures, and reduce it to writing, you should be safe from sanctions
  • Get a section 502 claw-back provision embodied in a court order
  • Sanction cases-Repeated misrepresentations and a failure to be careful cause most of the sanctions, regardless of the provision the Judge may cite as authority for imposing sanctions.
The best practice comments were interrupted when Wayne C. Matus,  Partner, Pillsbury Law Firm, asked a question from the audience that caused a noticeable "pause for reflection" by the Judges before they could answer.  He asked if there was ever a situation where the standard for Legal Holds was going to be always on hold?  He gave the hypothetical of a construction company that knows there will always be litigation with a certain size development project, so from the beginning, they can "reasonably anticipate litigation."  After giving it some thought the Judges, while not answering the hypothetical directly, did point to similar industries, like pharmaceuticals, and technology development, where future litigation is always a consideration.  Since I have advised clients in this area, I commented to Wayne afterward that it was almost an "unanswerable question" and jokingly asked if he had ever been banned from participating in Q&A with Judges Panels because he asked such tough questions?  The truth is, tough questions like that are the best part of these panel discussions.


Judge Collings clarified the role of inside versus outside counsel: "What is subject to legal review is the role of outside counsel."  He recognized that making money for the corporation and keeping money for the corporation (a penny saved is a penny earned) is a major goal of inside counsel, but noted they will run into problems if Legal Hold notices are not going to the correct custodians or they are not being issued on time.

Judge Laporte referred to the Pension Committee case to remind us that Circuits have different standards for issuing Legal Holds.  She also commented on Judge Shira Scheindlin's recent dicta about always issuing a written hold.  Judge Laporte observed that "when you have a small family or small business litigant, it could be a very different situation and standard.  On the other hand, why wouldn't you issue a Legal Hold?"

Patrick Oot, a well-known eDiscovery expert and Sedona Conference participant made an interesting point from the audience about wage and hour disputes and when you may not want to issue Legal Holds in the standard fashion but might choose to separate the Legal Hold policy from the class certification.

Great point from the Judges on reviewing your own Legal Hold procedures:  "Imagine if you have to explain what you are doing to the Judge later."  For example, even an email is now a written record of what you did to issue a Legal Hold and it creates a trail.  Discussing the Quan case and text messaging, there were conflicting views on what the company policy was.  The Judges recommended audits regarding private versus company usage.  Best practice, "Have a clear cut policy" and people need to know it!

I had one what I like to call "cringe moment" when Judge Collings mentioned that lawyers are going to have to learn about technology to adequately represent their clients in court.  He mentioned the long tradition and ability of lawyers to be able to learn a great deal about a particular subject matter in order to prepare for trial.  They can study and learn an amazing amount of information in order to explain the subject to a judge and jury.  While judges are never "wrong," they are only "misinterpreted," my worry is that too many techno-deficient lawyers will believe they can learn the technology and its language in a few weeks.  They can not.  To them, in addition to offering my expert services (shameless plug), I suggest a more appropriate analogy would be like trying to learn to speak French in a few weeks.  In other words, learn what you can, but bring your expert interpreter along.  Merci beau coup...

April 9, 2010

What's that up in the Cloud Part 2? Do you have a Policy?

by Cary J. Calderone, Esquire

In the first article on the subject I presented an overview of some of the risks with moving your company data and/or applications to the Cloud (link to Part 1). This article is about moving to the Cloud whether you want to or not. Let me explain. Do you think you are in control of your companies' data? Maybe, or maybe not! Companies like Dropbox, Mozy and many others are offering free cloud storage to users. And, we are talking about free gigabytes of storage. Enough to hold far too much of your important, privileged and/or proprietary company information. These new product offerings are simple to use, and extremely easy to setup in a matter of a minute or two. This means that if you do not have a policy on storing your work product off site, like on USB flash drives or tapes, then you had better at least get one for Cloud storage. USB ports can be disabled. Stopping user access to all the Cloud storage sites would be very challenging. This means all a user has to do is download a small application, setup a folder on their desktop computer, and from that point forward, anything they place in that folder gets copied to the cloud. As a warning to all my potential clients, you do not want your first knowledge of this new technology coming after you have been served with a Request for Production in a lawsuit.
Now, personally I think this is the greatest thing since sliced bread, or, at least the greatest thing since free personal email accounts. I have setup test accounts with both Mozy and Dropbox. Having the latest copy of my draft blog post available on my netbook, my laptop, or my desktop machine, is a great time saver and backup mechanism. In the past, and even though I seldom need to share my information with another person, I have wasted countless hours and email storage space moving my data from one of my computers to another of my computers via USB or email. I no longer have to do this. Additionally, if I am ever away from one of my computers, I have the option of getting to my data by using any computer that has internet access. In conclusion, two quick words of advise: 1) If your company policies do not cover Cloud storage, they should. 2) If you are a lawyer making a discovery request or taking a deposition, you should know how to ask about this stuff.

March 5, 2010

IQPC eDiscovery Summit in San Francisco coming in April

by Cary J. Calderone, Esquire

For those of you who do not think that a couple of my blog articles will be enough information for you, then consider attending the eDiscovery Summit in San Francisco on April 26-28. I plan on covering the Judges Panel on eDiscovery with U.S. Magistrate Judge, Elizabeth D. Laporte, and another session focused on Cloud Computing and eDiscovery. In 2008 I covered a keynote delivered by Judge Laporte. (link to 2008 keynote article) so I am looking forward to getting an update from her. As I have mentioned on this blog previously, it is a rare treat to be able to get eDiscovery information and education directly from judges, as opposed to interpretations by other "experts" and "pundits." U.S. Magistrate Judge Robert B. Collings is also scheduled to speak. Additionally, there will be quite a few inside counsel who will share their "hands-on" experience with eDiscovery.


February 25, 2010

Legal Tech 2010-Best Practices in Compliance and Email Management in the Cloud

by Cary J. Calderone, Esquire

The participants (listed at end) on this panel had many years of eDiscovery experience and came from a variety of backgrounds including legal, consulting and product vendor. This was like getting a "Quick Tips" guide to eDiscovery because they chose to a conversational approach instead of doing a lecture and presentation. They started off first, by agreeing with Malcolm Gladwell's keynote comment, "we are in massive information overload." Then they got right at some important distinctions for the new language describing eDiscovery and, in some cases, updated the definitions for some of the old labels. For example, they talked about the "Cloud" and basic definitions, but the panel thought it was necessary to be more specific now and gave examples:
  1. Public cloud-3rd party provider
  2. Private cloud-you set it up yourself
  3. Storage Cloud-as opposed to applications
  4. Infrastructure-the network behind the Cloud
The driving force behind the use of the Cloud is that "head count is expensive."
Peter Lesser believed that private cloud is the safest way to store and use data because then users keep it off their laptops, etc.

The panel drilled down on Infrastructure and asked about variables like:
  • International considerations.
  • Where is the data really stored?
  • What about Virtualization?
  • Can you identify and distinguish between "primary" and "backup" data?
Tom Gelbman commented that the de facto Policy might be just to keep everything forever.

They noted some of the really difficult questions. How are you going to apply your Retention Policy? Where is the data? For example, a Swiss based parent company with data kept in Arizona? Is it now subject to Arizona and US jurisdiction?

What happens when a broker-dealer uses Facebook but can't capture the Facebook data-that is a problem under the current rules. And, if Corporations think they are just going to shut these things down “they are delusional.” Between, Twitter feeds and text messages etc., even with policies in place, they may be unenforceable. "Behavior does not change because you have a policy." This author would disagree. I believe that you can change some behavior with a well designed policy and training but agree that just having a policy, is seldom enough.

They claimed that without some sort of auto-classification tool, the management of the data is impossible due to the volume. They also recognized the sobering fact that it is much easier to get money budgeted for eDiscovery than it is for Retention. No arguments from me! Oil changes and routine maintenance seem to get quickly cut from budgets, but once the car breaks down, you have no choice but to call the tow truck and prepare for a big bill from the mechanic. Is your company being "proactive," with litigation preparedness, or, will they have to be "reactive" and pay for the blown engine when litigation erupts?

Tom Allman's Cloud checklist:
  • Can you suspend all auto deletion and move the data to an eDiscovery location?
  • What about meta-data?
  • Do you have backups to the cloud?
  • Neither Google nor Microsoft will implement legal holds. There is no Microsoft product to stop users from deleting a message. Journaling is the only option. Do you have it?
  • Does the Cloud help with cleanup of the digital landfill? Yes, it can.
Rosenthal and Lesser noted that the move to the Cloud has a positive effect in that it “Forces companies to engage in legacy retirement programs.”

Allman added one of his favorite funny-but-true tips, If you have backup tapes that are 25 years old, make sure when you sell a division, all the tapes go with it!

Weiss believed for many instances of email, you keep it 10 years then delete it, because access to it becomes more and more difficult.

Rosenthal added that legacy program are linked to applications and clients. So how would you ever be able to sample, search and analyze the data?

They posed another great question: Can you determine the value of the data?
Lesser-Storage is getting cheaper every year but the cost of the people to organize it far outweighs the cost of storage.
Brian Weiss added that yes, storage is cheap, but retrieval is expensive. Moreover, to scale up to index large amounts of data is still very expensive.

The final thoughts or hopes were that in five years from now, there would be no applications stored locally on computers and there would be much better search tools.

We shall see!

Panel participants:
Tom Gelbmann, Managing Director, Gelbmann & Associates
Tom Y. Allman, Editor, The Sedona Principles
Peter Lesser, Director of Global Technology, Skadden, Arps, Slate, Meagher & Flom, LLP
John J. Rosenthal, Partner, Winston and Strawn, LLP
Barry Murphy, Principal, Murphy's Insights
Moderator:
Brian Weiss, VP eDiscovery and Information Governance, Autonomy


Legal Tech 2010-A couple of neat new DRED products even smaller businesses can afford.

by Cary J. Calderone, Esquire

Let me start by hedging a bit. I am not recommending these products. I played with only demonstration versions. I do not test and review products unless I have been specifically hired by a client to help them decide what product they should purchase for their particular needs. However, at this past Legal Tech Show I was happy to demo two new products that smaller companies could afford to use. This is good news because in the DRED space, most of the initial products released targeted large clients and installations and had pretty large price tags. It is hard to imagine a smaller business working with a product that starts at 300k to solve a retention or eDiscovery problem. The two products I noticed: 1)Legal Hold Pro by Zapproved and 2) BitFlare by SunBlock Systems.


These are both products that may help many smaller businesses. Legal Hold Pro allows a customer to track Legal Holds, and more importantly, all the communications around the Legal Hold (LH). There are many challenges with issuing LHs. The obvious issues involve when the LH should be issued and what it should cover. However, it is also critical that the LH is adequately communicated to the correct custodians and that you can validate the communication for compliance with your LH policy. Legal Hold Pro is a SaaS product (in the Cloud) that helps users track not only the initial distribution of the LH but also, subsequent updates. I think the best feature may be that it helps users remove the LH when it is no longer necessary. This is an issue that has not been discussed as much. Even those who are proficient at the initial LH process will admit that they are much more disorganized when it comes to removing the LH. And, if you are holding data, whether you need to be or not, it now may be subject to a new discovery request and/or a new LH. So the product may help you legally "clean house" a little better.

Similarly, BitFlare gives smaller companies the ability to lock down computers for LH or data forensic purposes. There are other forensic tools, some of them more affordable than others, but the focus of BitFlare is that a non-techy can follow simple instructions and secure data on a computer, in a fashion that Bitflare claims (I do not know if it has been tested in court) will preserve the chain-of-custody and accordingly, preserve its use as evidence. BitFlare is not a Cloud or SaaS product, but rather is a software product that comes on a bootable CD disc and can be run on any laptop or desktop computer (not sure about Operating System limitations).

They have an interesting pricing schedule. You can download the software for free and use it (provided you know how to burn an ISO cd) but then if you want the spreadsheet that lists the content on the computer, it will cost you $250. My hunch is they use this approach so when you think you might need contents for a LH you can lock it down. Then, and only if and when you need to analyze the data, you can pay $250 to see what is actually on the computer.

Once again, I have not used either of these products other than the demo versions, so you will need to test and verify that they will work for you. Still, it is very nice to see a few products capable of helping smaller companies tackle issues around DRED law. Let's hope this is just the beginning and there will be more affordable products to help companies become and stay DRED ready.

February 16, 2010

Legal Tech Keynote by Mark Howitson of Facebook-Social Media and eDiscovery

by Cary J. Calderone Esquire

I had the pleasure of listening to Mark Howitson (aka Howey), Deputy General Counsel of Facebook, Inc. deliver the keynote address on Day 2 of Legal Tech. He started off with some staggering facts about Facebook:
  1. Currently, ½ of all Americans over the age of 14 use Facebook.
  2. 350 million users have logged into Facebook, in just the last 30 days.
If you think this social networking thing might just be catching on, you are right!

Howey came to Legal Tech to talk about Social Media and eDiscovery or, as he described it, dealing with Social Media and the information that he provides for discovery requests.
He divided his presentation into two responsibilities of managing data at Facebook:

1) Social media and discovery
  • Social media is going to be all around us-There is already an application (Forceware) that uses the iPhone GPS to provide live location reporting
  • The technology is everywhere
  • The technology is here to stay
Howey mentioned things he can't and won't do. He distinguished between when the law “allows” disclosure versus what it “requires” for civil discovery and this is a critical distinction because Facebook is dealing with huge volume.

In this regard, Howey relies heavily on the
Electronic Communication Privacy Act (ECPA) and the Stored Communications Act (SCA) CA 18 USC 2701 for wire intercepts, and Section 2702a for “covered provider,”“remote computing,” and “electronic communications services.” He noted that there is an issue of when Facebook may provide information to a requester under Section 2702b and the substantial legal necessity of having “lawful consent.” Customer Records would be covered by Section 2702c for example, if a subpoena is asking about User X and all communications. In that instance, even with a subpoena, Facebook can only give basic subscriber information.

Howey is “itching for a fight” as he wants user information to be declared “content” and therefore completely protected from disclosure. The SCA was created in 1986 so Howey believes it is time that the Federal Court clarifies the rules with case law that involves present day fact patterns and current technology.

He discussed the Colgan Air case involving Workers Compensation (WC) for a flight attendant. The WC appeals board sanctioned Facebook $200 a day for not providing the data about the flight attendant to Colgan Air but the appeals board later backed off because they recognized that Facebook was never provided the required consent.

Howey really had the audience pondering the question of what is “lawful consent?” For example, was compelled consent of parolees adequate under the SCA? And what about students subject to random drug testing?

There was also a case from Bozeman, Montana where job seekers were wrongfully required to list their social network screen names so they could be searched! And he talked about another case in Houston where they where the interviewers asked for the interviewee's Myspace password in order to review their Myspace page. The interviewee sued and won.

He believed the way to circumnavigate this law would be for a interviewer to ask the applicant to, “be my friend on Facebook?” This would appear to be a lawful approach as long as it is not coerced.

2) Managing Discovery at a Communications Company

  • We now live in a world with chat and Wikis which need policies written and enforced company-wide.
  • Howey described the basic tenets of discovery when it came to corporate material, which is a “yes” for discovery, versus personal material and items protected by the SCA, which would be a “no.”
  • There are still some gray areas, like email notification about Facebook communication which is residing on your computer system. Is it covered by SCA or not?

As a basic precaution to protect your privacy, he mentioned, “don't connect your business email to your Facebook account.”

When it came to the second item, “Managing all this Content” he had the following suggestions:
  1. Fee arrangements with law firms
  2. Single discovery counsel for all firms (I found this interesting but would really like to know how this could work given conflicts of interests and competition amongst law firms)
  3. Flat fees that delineate responsibility
  4. Companies first need to cut a deal with their outside counsel.
He mentioned some innovative firms and thought it was “insane” to pay law firms full freight. Howey also believed that the days of rooms full of people and monitors doing document review should end. He championed leveraging technology to keep costs down.

One of the high points of the entire conference for me was that Ms. Zubulake of the seminal eDiscovery decisions was in the audience. I have personally been involved in many debates about the correct pronunciation of her name. To his credit, once Howey found out she was in the audience he asked her. It turns out the first syllable sounds like “zoo” and the last syllable rhymes with “cake.” Lawyers and judges who read this may now rejoice!

On balance, Howey gave a very fun and informative keynote. He provided some answers and supporting authority and most definitely raised awareness to many of the critical issues going forward with eDiscovery and Social Media.

February 2, 2010

European Union data: What are the rules?

by Cary J. Calderone, Esquire

Those who attended this session at Legal Tech learned some interesting things about data protection in the European Union (EU) from a very impressive panel of experts (bio information and links below). My first foray into this area, the conflicts between EU and US rules governing electronic data, began about 3 years ago. While researching this subject for a particular client, I learned that international corporations had virtually impossible responsibilities to balance and implement. It became apparent that most issues would remain unresolved even as the best of international companies made progress towards becoming compliant company-wide. I was very interested in hearing about the current state of the EU and US data rules.


Nigel Murray offered some background information:
  • January 28, 2010 was the 4th European Data Protection Day – they have made it a holiday!
  • The EU Data Protection Directive will be updated to reflect new technology.
  • EU Data Protection rules will be written so users know when their personal data may be stored and that they have the right to say “no!”
  • The European Union has 27 member countries-No Norway, Switzerland, or Lichtenstein.
  • Bulgaria, Romania, and Turkey are not in the EU, but they are trying to join.

Judge Peck began by describing why the EU and US rules are in conflict. He explained that in the US the standard for discovery is information that is “reasonably calculated to lead to the discovery of admissible evidence.” In the US, even a claim of Confidentiality is not a basis for refusing to disclose or produce data. Sensitive items relating to HIPAA, Social Security Numbers, or credit card information would be redacted in accordance with a protective order or agreement, but the information is discoverable. On the other hand, under EU rules, Privacy is a fundamental right and anything that contains personal information, broadly defined as anything that can be used to identify a person, (see Definition Personal Information) can not even be searched, let alone collected or disclosed without the individual user's un-coerced consent. Judge Peck commented that “in the ideal world, a US Judge does not want to have to worry about EU or Asian rules” but we are not in the "ideal" world.

A few legal cases were discussed by the panel to show that the trend has been, if data is in the US, then Courts have been very hesitant to use EU Data Protection rules to keep it out.

Other observations:
  • Within EU jurisdictions, moving data from country to country also causes problems. If it seems odd to us in the US, remember that the US does not have a history of countries crossing borders to expand their empires.
  • There are times when cooperation can work. George Rudoy described one instance when the representatives of a company made him take a drink with them to show that his data collection would be used for only legitimate purposes. It may have been water. It may have been vodka. His willingness to participate reassured them.
  • Maura Grossman shared that no matter what your risk profile, it would be a best practice to establish relationships and get input from local counsel. She explained that there are many data protection rules where the exception for litigation is specific to litigation in that country. If your matter is filed in another country, even another EU country, the exception simply does not apply.
  • Consent is sometimes an option but not always. There are stringent standards to follow for gaining consent, and in some cases, consent of the individual is irrelevant.
  • Another best practice is to be “super-surgical” in targeting requests at specific data, and keeping the scope of the request bound by the borders of that particular country. What makes this very tricky is that it is not just moving data that causes a problem. Merely accessing the data can violate the rules! If data is hosted in Germany, a lawyer violates the rules if he accesses the data from his office in NY.
  • If a corporation has been freely operating with its worldwide data in an “open” fashion i.e., journaling all email communications in the US then Judge Peck believes it is more likely a US Judge will not protect that information from disclosure under EU data protection rules. Judge Peck says that “if it is here”, it comes in subject to comity with foreign countries.
  • George Rudoy and Browning Marean echoed that we should follow local rules and implement the safest technology we can.
  • Nigel Murray also stresses that it is critical to have “local boots on the ground.”
  • Maura Grossman pointed out that there are some very specific and important differences in the International community. For example, before heading to China to take a deposition she learned that American lawyers are not allowed to take depositions in China. She would have been jailed!
  • Browning Marean mentioned that the Pension Committee (Judge Scheindlin) case reminds us that failure to issue a Legal Hold when litigation is reasonably anticipated is gross negligence. He also added that Legal Holds are more effective when created and dispersed internally than when an outside law firm issues them.
The panel considered quite a few other issues that make EU data discovery more complicated, like:
  • Where is the data housed?
  • What if it is in another country in a cloud?
  • Who controls the data in a parent-subsidiary situation?
  • What is considered “reviewing or accessing the data?”

In conclusion, the rules are still evolving and for now, you need very competent and probably local advise to perform a risk/reward analysis to determine what you may or may not do with EU and other "non-US" data. After 3 years of following this tricky legal area, I had hoped there would be a few more straight answers and solutions, but not yet.

Panel Members:
George I. Rudoy, Director, Global Practice Technology & Information Services, Shearman & Sterling
Nigel Murray, Managing Director, Trilantic
Honorable Andrew J. Peck, Magistrate Judge, Southern District of New York
Browning E. Marean, Partner, DLA Piper LLP
Maura Grossman, Counsel, Wachtel, Lipton, Rosen and Katz
Senior Master Steven Whitaker, Senior Master of the Senior Court of England and Wales
Chris Dale, E-Disclosure Information Project
Vince Neicho, Litigation Support Manger, Allen & Overy LLP

Legal Tech 2010 Begins-First Keynote

By Cary J. Calderone, Esquire

This is the first post from Legal Tech 2010 in New York. Russell Stalters delivered the first keynote entitled "Don't build your E-Discovery Program on a Digital Landfill." Mr. Stalters discussed some of the very real-world issues that occur when companies try to manage their data better.
More and more, companies realize their attorneys and IT professionals do not have the necessary skills to manage data from the other's perspective. They often lack an understanding of the technology, law or the business reasons and realities around information management. Mr. Stalters believes companies would be wise to create a new C level position specifically in charge of RIM. Others have commented that Discovery Counsel or Information Czar types of positions are critical to success but he insists that they be at the C Level to get the job done well. He claims that even CIO's have had a different focus than what is necessary to apply best practices to managing information company-wide. He gave a brief overview of the Greenfield approach and how it can be employed. In conclusion, he never mentions the word "easy" but he insists that a fully compliant and functioning system can be achieved.

December 2, 2009

Golf, Tiger Woods and ESI???

by Cary J. Calderone, Esquire

Even though I have been a golfer (those who know me might say golf nut) for quite a while, I never thought I would be blogging about a famous golfer here. When does golf ever have a connection to Document Retention and Electronic Discovery? Never, right? WRONG. Enter Tiger Woods and the media circus that has grown due to his recently admitted "transgressions." Of course there are many of the typical "he said, she said" stories dominating the media outlets, much like they do when Tiger is dominating a golf tournament. After all, Tiger Woods is always big news. However, what is most interesting to me is that if lawsuits are eventually filed, will Tiger be in even more trouble for attempting to destroy the evidence of his "transgressions?" Has he failed to preserve relevant Electronically Stored Information (ESI) relating to a reasonably foreseeable legal matter? If the answer is yes, then Tiger may have exacerbated his problems. Let me explain.

Tiger initially claimed the news stories of marital problems and affairs were unfounded and he issued a statement on his website www.tigerwoods.com. Did that mean litigation could be "reasonably anticipated?" Did his wife mention "divorce" in one of their private "discussions" about his "transgressions?" If the answer to either of these questions is "yes" and he then went and tried to delete any damaging text, voice or other messages that would have made him look guilty, he may be in serious trouble. Tiger may face civil and/or criminal penalties under the Federal Rules (FRCP), and many state laws, that prohibit spoliation (i.e., destroying or altering) of potential evidence.

For example, there may be an issue with the voice mail Tiger allegedly left (it sure sounds like his voice but you be the judge) for his "friend" wherein he instructed her to change her voice mail message because his wife "went through his phone" and "may be calling." On the one hand, he has publicly claimed outrage at the press: "the many false, unfounded and malicious rumors that are currently circulating about my family and me are irresponsible." Moreover, one of his alleged mistresses hired the famous attorney, Gloria Allred, and issued a statement that the rumors are not true. Sure sounds like a lawsuit is brewing if it has not already been filed! On the other hand, Tiger is trying to get rid of messages that connect him to the alleged mistress and would indicate that the stories and "rumors" are actually fact-based and true.

Attorneys under the old rules and paper documents, would almost always go public and threaten to sue the newspapers and magazines on behalf of their celebrity clients. That may have been the standard operating procedure historically, but today, that kind of public condemnation means your client shouldn't also be going through their phone, and email accounts to try to delete potentially relevant material, no matter how much they would like to do so. In the days of paper evidence, lawyers might interview their client at the outset and ask if any damaging material "could be located?" The client could honestly answer "no" to that question when they knew they were completely innocent or, they had done a fantastic job of shredding, burning and burying any damaging documents before meeting with the lawyer. Nowadays, the new rules and technology have changed the question and perhaps the best initial public course of action because it is not a matter of if, but rather, when the damaging material will be "located."

This blogger will continue watching and reporting to see if and how Tiger navigates his way out of this "hazard."

September 27, 2009

What's that up in the Cloud? Is it a bird? Is it email? Or, is it a Health Club?

by Cary J. Calderone, Esquire

Cloud computing is HOT! Hosted exchange solutions are being advertised to every small, medium, and large business. Google, Microsoft and other big players are promising their cloud solutions will provide security and hassle free email and applications without having to worry about more infrastructure and personnel investments. They may even include archiving and record retention management features to help with DRED (
Document Retention and Electronic Discovery). Lower cost and more service, it sounds great, but is it?

Time for a confession here: I have been in the Cloud for years. In fact, I have been operating in the Cloud since long before it was called “the Cloud.” Years ago, I decided I wanted to be able to travel on vacation to Europe or to Hawaii, without lugging a laptop. So I hosted my business account through Yahoo. This meant I kept my email at Yahoo (while using my own domain address) and only downloaded copies of my email as backups. Therefore, wherever I was, if I had access to a computer in an internet café, or a library, or could borrow a friend’s laptop, I could access my email and attachments and work. I even started to store my “working documents” in a secure online briefcase so I could review and edit work product if I had the need and if it was not already in my email box as an attachment. Even though this was years before Blackberrys and iPhones made transportable email commonplace, I was mobile.

Chances are some of you have been Clouding too. If you have an email account with Yahoo, Hotmail or Gmail, then it is likely you have been in the Cloud. Or, as I describe it, you do not need your “personal computer” and installed applications to work with your email. Any computer with internet access will suffice. And yet, as a self-proclaimed longtime happy Cloudy, why am I not ringing the bells, extolling the virtues, and pushing companies to make the move to the Cloud? The answer is because, I workout. Or, more importantly, I have always had a membership at a health club. Non-sequitor you say? Please keep reading.

Back in the health club boom of the 1980s, many health clubs sprouted up creating an ample supply for those people who decided that a healthy and active lifestyle was desirable. However, I noticed a problem with almost all new clubs. When they first opened they had new equipment, reasonable membership deals and a few members. I remember going at 6:30 pm, jumping on the machines I needed, and in 45-60 minutes, I was out of there. But with the success of the new health club came more sales and more memberships. Over time the equipment ran down and the lines to use it grew longer. At some point it became necessary to schedule workouts for non-prime times, or just skip them. Do you still feel like this analogy is misplaced? Then check out this article by Brett Winterford, "Stress tests rain on Amazon's cloud" or the followup article, "More data released on cloud stress tests." The report following testing of three big service providers for seven months indicates that among these very big Cloud providers (Amazon, Google and Microsoft), there are already noticeable performance issues with on-demand services, especially during peak hours. And, even more distressing, the report finds these performance and accessibility issues are “regular” and that the Cloud providers do not provide performance monitoring tools so that Cloud customers may track performance. The report is enough to make this happy Clouder worry a little that the health club analogy is spot on.

There are other critical issues in considering the Cloud, like security. How secure is your company data in the Cloud? On this issue, I would need more information to know if the Cloud would decrease or increase your security risks. How experienced, well-staffed and well-funded is your IT department? Perhaps your data is actually more secure in the Cloud than it is on your old and out-dated servers. The best argument I have heard for mistrusting the Cloud is that, if a security breach occurred, would you even know it? Do we trust the Cloud providers to quickly stop any breach and report it? Do we trust them as much as we trust our internal IT and security staffs to report a breach? This is a very good question to ponder before making the move to the Cloud.

Truthfully, I feel odd writing this post. Here I am, a long-time Clouder writing about potential pitfalls with Cloud computing. I have been very happy with my Cloud experience and have had only extremely rare instances of any problems or issues and these issues would have likely occurred with even the best internal IT department running my email server. Still, happy as I have been, I have always had the option to use another email account if one Cloud account quit working. When the health club became too crowded, I just joined a different gym. Your company cannot easily just switch and join a different gym or Cloud! Yogi Berra could have been speaking about our modern Cloud solution providers when he commented on a restaurant: “Nobody goes there anymore. It’s too crowded.”

July 31, 2009

New E-Discovery Rules in California: What does this mean for you?

by Cary J. Calderone, Esquire

With no fanfare our Governor, Arnold Schwarzenegger, signed into law AB 5, the California Electronic Discovery Act ("CEDA") (Full Text). The only surprise to those of us who practice in this area was that it did not get signed into law last year. Most believe it was delayed solely due to California's pressing budget problems. California is the home of Silicon Valley and the High Tech industry so the laws in our state typically lead the way when it comes to considering their effect on technology and business. In California email correspondence has been legally enforceable as a "written instrument" since the mid 1990s. It made no sense that one state after another, except California, was adopting rules to mirror the e-discovery rules contained in the Federal Rules of Civil Procedure and thereby, acknowledging that business disputes were now dominated by Electronically Stored Information ("ESI") such as email, word-processed documents and databases etc. These states recognized the importance of having specific discovery rules around ESI and yet, California did not. Now that California has acted what does this mean for your company when it operates in, or is subject to legal proceedings in state courts in California?

First, all those stubborn attorneys who used to tell me that they did not need to worry about Legal Hold Notices, Email Procedures and Record Retention Schedules, because they never were involved in Federal disputes, no longer have that weak excuse. It was a weak excuse because under the old California discovery rules, litigants and their lawyers were affirmatively charged with the duty to protect potentially discoverable materials. In most cases, destroying "evidence" can be charged separately as a crime. There was never any exclusion for emails and ESI and in fact, emails and ESI have been critical pieces of evidence in many criminal and civil matters for at least a decade.

Second, not only is that lame excuse gone, the California rule requires that attorneys from all sides of a litigation matter will need to "meet and confer" 30 days prior to the Case Management Conference. This means they will need to discuss ESI and what/how it will be preserved and exchanged during the discovery process for state legal matters, just like they already must do for Federal matters. Do you know how much ESI you have on your network and in other places you control? Do you know where it is? Can you search it? You should be able to answer a resounding "YES" to these questions. Otherwise, it means you may end up litigating from a weakened position.

Some commentators believe the CEDA modifies the Federal Rule around "inaccessibility" of data as it may be used to defend from producing materials in a litigation matter. I believe the CEDA merely does a better job of explaining the real world arguments that occur in front of the judge. Namely, the judge will ultimately decide whether or not the information is "reasonably accessible" on a case by case basis. Judges have never been fans of an attorney conducting a cost escalating "fishing" expedition during discovery, but if there is a likelihood that important information is only available in one location, there are very few circumstances when a judge will not want that information to be retrieved and searched. The idea is that "Justice" is about finding the truth, not about being able to hide the truth from the judge.

Now it pains me to admit this, but in some ways, if your company has procrastinated and delayed having an Assessment Report and updating its ESI policies and procedures, you have benefited in that the software programs and procedures for accomplishing these tasks are better now and, in some cases, even cheaper. The bad news is that you have at least 2 more years of data to organize, review and remediate. So the longer you wait, the more likely the process will become more difficult and more costly. Will your company be like so many others out there that waited until they got tagged by losing a legal matter or got sanctioned for mishandling ESI? Or, those that had to settle a matter because they could not find their evidence to prove their case, or, they could find it but it would be cost-prohibitive to produce it in a defensible manner? Or, will your company need to feel the sting of a hefty discovery sanction to be motivated to organize their ESI? In a prior post, I mentioned performing a Google search for "million dollar discovery sanctions." There are even more now than there were the last time I mentioned it!

June 12, 2009

Kermit was right: It’s not that easy, being green

by Cary J. Calderone, Esquire

At a recent ARMA Golden Gate chapter meeting presenters gave real-life accounts of two law firms that had taken on the challenge to become “Green Certified.” Even if you do not believe Al Gore’s reasoning for going Green and that “the debate is over,” going Green may serve an unintended but very useful purpose. It is one more justification for updating the document retention practices and policies in your organization.
One obvious and continuing hurdle to becoming document retention and electronic discovery (“Dred”) ready is the cost. IT, Legal, Compliance may need to make significant investments in new technology to better manage electronic data. Even if you have adequate hardware and software, employees may have to devote more time and effort to help the company achieve and maintain this goal. Even though it is less obvious, the work involved can be substantial and it may affect HR, IT, Legal, Compliance and every other department in your organization. Unless your company is currently operating with under-worked and under-utilized employees (LOL-very doubtful) the people in these departments already have full-time responsibilities and making the move towards Dred-ready means a lot of extra time involved in reviewing and updating retention schedules, policies and procedures. It would be nice to be able to dangle another reward carrot and justification for doing the work. Going Green can really help justify the cost and effort of this often arduous undertaking.

At this talk, I expected to learn of great new paperless approaches to records management but instead the “real-life” examples centered on trying to save paper by mandating duplex printing, while at the same time demanding that 100% consumer recyclable paper was being used. I was surprised to learn that this type of recycled paper can cost 3-4 times more than standard copy/printer paper. This conflicted with my stated purpose of using “greening” in connection with Dred to make it more compelling. However, from my perspective, pushing towards Dred compliant and avoiding most of the printing of electronic documents would make for a much “Greener” approach and avoids the issue of spending extra money for more expensive paper. I certainly can respect that law firms would have an awful lot of time, money and focus on paper, so firms in less paper dominated fields should find it easier to pursue Green Certification.

And, although I was hoping to learn about some new groundbreaking scanning technologies or other methods to avoid using paper, we all should recognize that paper will continue to fade away in importance as better electronic document and email management systems are adopted. These types of systems work pro-actively which is by far the best way to avoid the need to print and store information on paper. For example, the Federal Courts have used the Pacer system for electronic filing for a number of years. California law has recognized email is the equivalent of a “writing” since about 1998. California has been considering adopting rules simlar to the Federal Rules of Civial Procedure demanding that Electronically Stored Information ("ESI") is exchanged to perform litigation discovery. These changes to the law, and the practices that are modified to comply with these changes to the law, will continue to reduce the need to focus much time and investment on scanning and other paper management technologies. The obvious flip-side to this is that file and email management and archiving will continue to grow in importance.

Since this blog is focused on Dred, I will not bore or disgust you with the helpful hints about recycling and composting office waste for the achieving a rating of Green. It is always nice to avoid waste but in a word, yuck. And you thought keeping the company lunch area clean and odor-free was difficult before! Given the volume of articles written and the number of presentations scheduled at trade shows, one thing becomes certain; in this day and age going Green has become hip. In summary, I will close with more of the insightful and, as it turns out, prophetic lyrics sung by Kermit the Frog, “Green can be cool and friendly-like.” (For Kermit singing on you tube : ) .

April 22, 2009

RSA Conference 2009-Mock Hearing and Appeal re: Spoliation of Digital Evidence

by Cary J. Calderone, Esquire

This was a treat. The Mock Hearing and Appeal, presided over by the Hon. John Facciola at the trial level and the Hon. Shira Scheindlin and Hon. Richard Kramer at the Appellate level, examined a spoliation challenge, its defense, and had an interactive discussion after the decision. It is very rare to get a chance to observe and learn about the decision-making process of any active Judge, let alone have veritable "rock stars" of electronic discovery, walk you through a hypothetical case and explain the issues as they rule, but that is exactly what the Mock Trial and Mock Appeal sessions provided. For those who do not have a legal background, all active Judges are governed by strict rules of professional conduct and must avoid "even the appearance of impropriety." This, in addition to the fact that they are monumentally busy, is why we seldom hear from these brilliant and experienced people on the evening news or talk shows. We are generally limited to reading their opinions and using them as precedent to argue similar case facts follow or can be distinguished from those previous cases. However, these mock trials are hypothetical and accordingly, the judges are at liberty to point out why the lawyers and witnesses won or lost their arguments. I implore anybody who is in the Legal, IT, Compliance, Records Management or Risk departments and, is in any way responsible for or involved in Records Retention or Electronic Discovery at their companies, to seek out this type of session at an upcoming conference and attend. Short of going into real court and observing (See Federal Court for Discovery-Be a Boy Scout) this type of presentation provides the best opportunity to learn why we are dealing with Record Retention Schedules and Policies in the first place.


In brief, the hypothetical involved an airline, who had an incident allegedly occur between a disgruntled passenger and an angry flight attendant. The airline had a document retention policy where handwritten Incident Reports from flight attendants would get entered into electronic format. Then the handwritten original would be destroyed. Also, there was a court ordered Legal Hold in place and the flight attendant shockingly had no recollection of the events that happened. It is not necessary to go through all the details that were discussed but a couple of important items relevant to Document Retention and Electronic Discovery are that: 1) Check to see if your company is actually following its Policy? Judge Scheindlin commented that "if you follow a policy that allows for routine destruction of data, before a duty to preserve it on Legal Hold arises, you are safe." 2) Is your policy reasonable or will it look like it is designed to eliminate any potentially relevant and/or harmful evidence? 3) Know your facts when it comes to claiming or defending claims of spoliation. For example, the Second Circuit does not require malicious acts. Mere gross negligence will be sufficient to justify an "adverse inference instruction" from the Judge.

At the trial level Judge Facciola ruled that the airline had disobeyed the Legal Hold when it destroyed the original handwritten document. Further, he found that the electronic version did not include a signature or an attestation from the flight attendant so the electronic version was not "complete" which violated the airline's own retention policy. He ordered an adverse inference instruction be given. An adverse inference instruction means the before the jury deliberates, the Judge explains that because this evidence was destroyed they may assume that it meant it was evidence harmful to the airline. Not good for the airline! On appeal, the panel overturned the lower court and found that given it was negligence and not malicious acts, the adverse inference instructions was too harsh and monetary sanctions would be more appropriate. Better for the airline, but they did not discuss the amount of the sanctions so it might not have been that much better.

When I expressed my condolences to Judge Facciola for getting reversed by the mock Appeal panel he said that he was very confident that the Appeal would have been reversed back in his favor at the mock Supreme Court level. :)

Panelists: Honorable John Facciola, United States Magistrate Judge
United States District Court for the District of Columbia
Honorable Shira Scheindlin United States District Judge
United States District Court for the Southern District of New York
Honorable Richard Kramer San Francisco Superior Court Judge
Stephen Wu, Esq. Partner Cooke, Kobrick & Wu, LLP
Hoyt Kesterson II Consultant
Randy Sabett Attorney Sonnenschein Nath & Rosenthal
Joseph Burton Attorney/Managing Partner
Duane Morris LLP
Moderator and Counsel for Mock Plaintiff: Steven Teppler, Esq. Senior Counsel Kamber Edelson, LLC

April 15, 2009

"Reasonable" is graded on a scale

by Cary J. Calderone, Esquire

The Silicon Valley chapter of ARMA International held an ITRIM (Trim your data) one-day conference recently and I was fortunate to attend the lunch panel discussion. The panel members, Grant Law, Esquire of Shook Hardy & Bacon, Nathan Walker, Senior Technical Marketing Engineer of NetApp Corporation, Lisa Ripley, CISSP, Electronic Discovery Manager of Sun Microsystems, Inc., and Greg Lipptez, Esquire of the Jones Day law firm, gave brief presentations covering many familiar data retention and electronic discovery ("DRED") themes: 1) You will get sued therefore having a Data Map that explains what you have and where you have it is critical.. 2) Legal needs to be able to listen to IT and vice versa.
3) There is a constant struggle between lawyers who prefer to keep very little data and IT personnel who keep as much as possible. 4) Too many organizations have too many employees who are “surprised” to learn they actually have a record retention policy (and this is especially bad when their legal team learns of this fact during sworn testimony). And finally, 5) the law requiring what you need to keep, is not static, it changes. While it is nice to know that concepts that I have previously covered in this blog are out there being discussed and adopted by more data managers and professionals, I would almost have declined to write about the discussion but for one really great quote from Nathan Walker. Answering a question on "how best to avoid getting into trouble" with the production of Electronic Discovery for Meet and Confer conferences and motions to compel hearings, Nathan said: “The more you appear to know what you have and where you have it, the more your threshold for “reasonable” goes down.” This comment was cheered by the audience and maybe the best simple explanation for why Records and Information Managers, IT, Compliance and Legal departments need to make retention schedules, train people to follow them, and continually monitor them. To paraphrase the famous Billy Crystal character Nando, on Saturday Night Live, when it comes to electronic discovery, it is more important to appear to “look absolutely marvelous” than actually "feel absolutely marvelous." Bottom line-it is always best to know what you have and where you have it.