Policies first then procedures or procedures then policies: Or, what comes first -- the chicken or the egg of document retention?
By Cary J. Calderone, Esquire
“Should we create our policies or our technology procedures first?” This is a question I am asked frequently by data consultants, lawyers, and IT people. At first I believed the question was a sign that people were looking to shift responsibility for document retention management away from themselves and onto someone else. (Who could blame them given all the new regulations and rules now in effect? See FRCP Changes) While shifting responsibility is a valid real-world motivation, in reality, the question itself raises good issues to consider by anybody considering implementing or updating an electronically stored data retention policy . Like many good questions, the answer is not a simple one.
My general rule would be to create a good policy according to your legal and compliance requirements and then coordinate personnel and technology to support that policy. This would put the burden on Legal and/or Compliance to set the policy and then IT to deliver it. However, by “good” policy I mean something that should take into consideration the capabilities of the current hardware, software, and usage. Too many times in my early technology consulting days I would be retained to find and recommend a software program that could do XYZ and I would research the client’s existing applications and discover they already had programs with the ability to do XYZ, or something extremely close to it. However, nobody knew enough about their own applications to work towards the desired result. So, I saved them some good chunks of money and everyone would conclude that I had brought value-added service to the gig.
Given that background, setting policies without looking at current systems, usage, and the reasons behind them is not a prudent practice. One could argue that Google provides a good example of one end of the spectrum. Their overriding company policy is “don’t be evil .” It follows that every action by every employee would be in an effort to support that policy. Sure must be nice for an attorney to represent a client with that honorable and well-published policy in place…makes for a great opening argument in any case or hearing. On the other hand, what might be an acceptable policy for your current “technology” (or lack thereof) may not fit well with your company’s plans for growth and innovation, and as I like to recommend, becoming a “lean, mean, litigation-ready fighting machine .” If the drivers behind policy are more related to operations, company image, security and other non-technology factors then you may indeed need to make an investment in new software and hardware and possibly personnel and training too in order to adequately support any re-aligned policies. And until the infrastructure is in place, changing your existing policies would not make sense, especially if they have already been approved, followed, and battle tested.
Furthermore, the ultimate goal is to manage your electronic data according to reasonable standards for your industry and under the legal requirements that govern it. The greatest sounding “policy” in the world will not help you if your practices and procedures do not support it or, at worst, conflict with it. If one policy statement says “X” and another policy describes, “Not X but Y”it will not withstand even a cursory legal challenge and therefore will have failed you in one of its basic functions. And, while I would not ever champion a mediocre policy, one that is strictly followed and supported would probably protect you more than a grandiose policy that is thrown out as a sham because it was not followed or was contradicted by other company documents and policies.
In conclusion, the answer to the question of what comes first is: it does not matter – and it does. Both Legal and IT, and other supporting departments will need to work together to make any policy legitimate. So, bringing both/all groups into the process early is the best and most prudent practice. Start by determining what your current policies are, where they are published, and why they were created. Then you can work to edit/modify/replace them with joint understanding of the likely overall costs and benefits.
May 16, 2008
April 30, 2008
Federal Court for Discovery? Be a Boy Scout!
By Cary J. Calderone, Esquire
During a recent lull between my legal business and document retention consulting, I visited my nearby Federal Court for an afternoon’s entertainment and to once again witness live the trench warfare litigants know as discovery disputes. I sat and observed a few discovery and case management hearings and in addition to being thoroughly entertained I found I had some very interesting things to report to those who would like to be prepared should litigation or a government hearing come their way.
Federal Court is still run as a dictatorship (notice I did not use the word benevolent as an adjective before dictatorship). For example, one judge explained that if there was a discovery dispute between the parties and the parties could not work it out themselves, he would allow them to file a joint letter no longer than 4 pages in length describing their respective arguments and then he would decide the outcome and which party would be sanctioned. I could not help but wonder what this judge might be like on a bad day after somebody perhaps submitted a 6 page letter to describe their dispute.
In another matter, lead counsel sent in a surrogate or “pinch-hitter-attorney” to take his place for the case management hearing. This resulted in a visibly irritated judge and an immediate issuance of an Order to Show Cause as to why that absent attorney should not be sanctioned. Ah, I remember what it felt like to appear in Federal Court…even as I quietly sat in the audience I started to feel a little of that old familiar stress in the pit of my stomach.
Much to my chagrin, I did not get to hear the arguments in a big discovery dispute over disclosing information about document retention policies and litigation hold practices because the parties were sent out like school children and told not to return to the judge until they could learn to get along and share their toys properly. In other words, when there were “issues” of contention presented by opposing parties, the judges immediately sent them off to “meet and confer” in the nearest available conference room. We are talking about seasoned, confident and high-priced attorneys getting ordered about and when they scurried out of the courtroom, one could not help but imagine that if they had tails, they would be drooped down between their legs like a family dog that had just been sternly reprimanded and sent off to the kennel.
If the end result of the hearing was that the Judge determined a follow-up hearing/conference was necessary, it was scheduled for 10 days out. Not a lot of time.
Now that you are more convinced than ever that you need to be prepared to head into litigation, I noticed one additional item that may serve you well when you undertake to map your company's electronically stored information. There is no set format required for this procedure. Some find it easier to work with word-processed documents. Others prefer to prepare spreadsheets and others might run a report from a database. After reviewing approximately 60 pages of the moving and response papers to see how these particular disputes concerning disclosure of retention and compliance policies would be argued I noted that they discussed transferring information between the parties via "spreadsheets." So apparently spreadsheets were the preferred format for this large case, and might serve you well if you are searching for a format for your own company's data map. Of course this does not mean you do not need to seek out your own local counsel to make sure they are happy with your format. After all, they are charged with the affirmative duty to become “familiar” with your computer systems so that they do not mislead the opposing party and the court when they propose discovery scope and methods.
Could There Be Even More Lessons?
The only hope for a party not entirely prepared to discuss the what, where, how much and the protection and collection of their discoverable material is that the other side is equally or preferably worst “not prepared.” Otherwise, if sanctions don’t immediately issue, Rule 30(b) (6) depositions will be scheduled expeditiously to find out specifically who knows where to look for discoverable material and how it is and will be protected from alteration and deletion. Although I did not witness a party getting sanctioned, sanctions were frequently mentioned. There was a study recently that found sanctions and/or inappropriate discovery conduct was found in almost 25% of cases of their survey sample. I don't need to run down a list of million dollar discovery sanctions here...a simple Google search of "million dollar discovery sanctions" will provide you with ample examples and words like "continuing trend" will often be found in the articles.
It also became apparent that companies contemplating their retention plans and policies need to understand better (especially if they have not previously spent time in Federal Court) that if you try to take an easy way out and present minimal information and hope for the best, there will be another high-priced lawyer or team of lawyers there to expose your efforts to the judge. And, if the judge is persuaded you have not taken your discovery obligations under the Federal Rules absolutely seriously, you will be in serious trouble. Federal judges were never known to have an abundance of patience. And now, the Federal Courts are extremely understaffed and at the point where one judge recently quit his post on the Federal bench to take a position with a state appellate court. I had the distinct feeling that the Judge relaying this story from the bench completely understood and related to the motivations of the defector. If you don’t believe this is an accurate observation please look at the size of the discovery sanctions being handed down (did you perform that Google search mentioned above?) and rethink your position. Defenses of negligence, oversight and malfunctioning technology have not saved litigants from multi-million dollar sanctions from mishandling their electronic discovery and those defenses will not work for you either. Especially now that with every new headline-grabbing sanction reported it makes it even more difficult for you to claim ignorance of the consequences.
Conclusion
As an attorney who appeared in Federal and State court many times to argue discovery motions, it was really fun to be able to listen and observe for an afternoon, and not have to think about making my own arguments on behalf of a client. It made me reflect about many companies I have worked with as legal counsel or as a consultant. Without question, some companies from my past would be prepared and would be easy to represent during discovery proceedings. Then there were those I would prefer to refer to other counsel rather than represent them in a crisis-reactive-mode to dig them out of an otherwise avoidable discovery mess. On balance, the most important lesson learned from my afternoon of observation to relay to you can best be described by the motto of the Boy Scouts of America, “be prepared.”
During a recent lull between my legal business and document retention consulting, I visited my nearby Federal Court for an afternoon’s entertainment and to once again witness live the trench warfare litigants know as discovery disputes. I sat and observed a few discovery and case management hearings and in addition to being thoroughly entertained I found I had some very interesting things to report to those who would like to be prepared should litigation or a government hearing come their way.
Federal Court is still run as a dictatorship (notice I did not use the word benevolent as an adjective before dictatorship). For example, one judge explained that if there was a discovery dispute between the parties and the parties could not work it out themselves, he would allow them to file a joint letter no longer than 4 pages in length describing their respective arguments and then he would decide the outcome and which party would be sanctioned. I could not help but wonder what this judge might be like on a bad day after somebody perhaps submitted a 6 page letter to describe their dispute.
In another matter, lead counsel sent in a surrogate or “pinch-hitter-attorney” to take his place for the case management hearing. This resulted in a visibly irritated judge and an immediate issuance of an Order to Show Cause as to why that absent attorney should not be sanctioned. Ah, I remember what it felt like to appear in Federal Court…even as I quietly sat in the audience I started to feel a little of that old familiar stress in the pit of my stomach.
Much to my chagrin, I did not get to hear the arguments in a big discovery dispute over disclosing information about document retention policies and litigation hold practices because the parties were sent out like school children and told not to return to the judge until they could learn to get along and share their toys properly. In other words, when there were “issues” of contention presented by opposing parties, the judges immediately sent them off to “meet and confer” in the nearest available conference room. We are talking about seasoned, confident and high-priced attorneys getting ordered about and when they scurried out of the courtroom, one could not help but imagine that if they had tails, they would be drooped down between their legs like a family dog that had just been sternly reprimanded and sent off to the kennel.
If the end result of the hearing was that the Judge determined a follow-up hearing/conference was necessary, it was scheduled for 10 days out. Not a lot of time.
Now that you are more convinced than ever that you need to be prepared to head into litigation, I noticed one additional item that may serve you well when you undertake to map your company's electronically stored information. There is no set format required for this procedure. Some find it easier to work with word-processed documents. Others prefer to prepare spreadsheets and others might run a report from a database. After reviewing approximately 60 pages of the moving and response papers to see how these particular disputes concerning disclosure of retention and compliance policies would be argued I noted that they discussed transferring information between the parties via "spreadsheets." So apparently spreadsheets were the preferred format for this large case, and might serve you well if you are searching for a format for your own company's data map. Of course this does not mean you do not need to seek out your own local counsel to make sure they are happy with your format. After all, they are charged with the affirmative duty to become “familiar” with your computer systems so that they do not mislead the opposing party and the court when they propose discovery scope and methods.
Could There Be Even More Lessons?
The only hope for a party not entirely prepared to discuss the what, where, how much and the protection and collection of their discoverable material is that the other side is equally or preferably worst “not prepared.” Otherwise, if sanctions don’t immediately issue, Rule 30(b) (6) depositions will be scheduled expeditiously to find out specifically who knows where to look for discoverable material and how it is and will be protected from alteration and deletion. Although I did not witness a party getting sanctioned, sanctions were frequently mentioned. There was a study recently that found sanctions and/or inappropriate discovery conduct was found in almost 25% of cases of their survey sample. I don't need to run down a list of million dollar discovery sanctions here...a simple Google search of "million dollar discovery sanctions" will provide you with ample examples and words like "continuing trend" will often be found in the articles.
It also became apparent that companies contemplating their retention plans and policies need to understand better (especially if they have not previously spent time in Federal Court) that if you try to take an easy way out and present minimal information and hope for the best, there will be another high-priced lawyer or team of lawyers there to expose your efforts to the judge. And, if the judge is persuaded you have not taken your discovery obligations under the Federal Rules absolutely seriously, you will be in serious trouble. Federal judges were never known to have an abundance of patience. And now, the Federal Courts are extremely understaffed and at the point where one judge recently quit his post on the Federal bench to take a position with a state appellate court. I had the distinct feeling that the Judge relaying this story from the bench completely understood and related to the motivations of the defector. If you don’t believe this is an accurate observation please look at the size of the discovery sanctions being handed down (did you perform that Google search mentioned above?) and rethink your position. Defenses of negligence, oversight and malfunctioning technology have not saved litigants from multi-million dollar sanctions from mishandling their electronic discovery and those defenses will not work for you either. Especially now that with every new headline-grabbing sanction reported it makes it even more difficult for you to claim ignorance of the consequences.
Conclusion
As an attorney who appeared in Federal and State court many times to argue discovery motions, it was really fun to be able to listen and observe for an afternoon, and not have to think about making my own arguments on behalf of a client. It made me reflect about many companies I have worked with as legal counsel or as a consultant. Without question, some companies from my past would be prepared and would be easy to represent during discovery proceedings. Then there were those I would prefer to refer to other counsel rather than represent them in a crisis-reactive-mode to dig them out of an otherwise avoidable discovery mess. On balance, the most important lesson learned from my afternoon of observation to relay to you can best be described by the motto of the Boy Scouts of America, “be prepared.”
February 1, 2008
Instant Messages as Business Records
Instant Messages as Business Records-A Common Sense Approach to Instant Messaging and Electronic Document Retention Policies
By Cary J. Calderone, Esquire
January 7, 2008
The motivation for this article occurred few weeks ago. I was sitting in the audience of a continuing legal education seminar on patent strategies. One topic that was of interest to me was a discussion of document retention policies and electronic discovery related to patents. A panelist, a senior attorney for a very large technology company, addressed email management as it related to litigation discovery. I raised my hand for clarification and asked, “When you say email, are you including instant messages in that definition or will you discuss them separately?” One of the most well regarded and experienced patent litigators in Europe, who was sitting nearby, leaned over and whispered to me, “excellent question!” The panelist however, rolled his eyes and said quickly, “we just don’t believe IMs are business records and don’t treat them as such.” My jaw dropped. According to the most recent Federal Rules of Civil Procedure (“FRCP”), instant messages certainly can and should be considered ESI “electronically stored information.” (See, FRCP Rule 26(f).) What constitutes a “Business Record” is defined by its content as well as its form and industry business practices. Current email retention policies were developed because using email to conduct business became a standard operating procedure. Similarly, use of facsimiles to create binding legal agreements developed over time. Although IM is not yet at that level of acceptance, some industries (just talk to your friendly stockbroker) already specifically track and retain IM to remain compliant with SEC and other regulations. In fact, many email applications track or “journal” instant messages in the same manner as email and in the same in-boxes.
I approached the panelist at the lunch break. He recognized me and quickly said, “maybe I misspoke.” He claimed that his company had just set a policy to not conduct any business via IM so they would not have to worry about managing or retaining IM messages for compliance and litigation purposes. This raises an important question: Is banning or severely limiting IM usage the best way to avoid having to manage it for document retention and legal discovery purposes? I don’t think so and here’s why:
IM is becoming more prevalent in research and development, marketing, sales and customer service. In fact, there are those who would argue vehemently that IM is becoming the most important business productivity tool within corporate enterprises. Perhaps you do not believe that IM is important to your organization. Here is a quick test. Have your legal department send an email to your department heads requesting comments on whether you should just discontinue or severely limit the use of all Instant Messaging applications on your corporate network given the complexity of the document retention and potential legal issues. A General Counsel I know did just that. Within 30 minutes responses indicated the regular use of 10 different IM applications, in addition to the company provided and managed application -- and that it would be very disruptive, if not impossible to prohibit IM use. These emails responses were real eye openers. Her reply was, what if we just did not have an IM policy, and we let people use whatever they desired and just told them nothing was to be used for official business and nothing should be saved. (In essence treating IM chat sessions just like a phone call, and when you hang up from a phone conversation, there is no written record.) Not even considering that the likely response from your IT director and other employees responsible for network security would want to quit their jobs rather than try to manage security for your new “open” (read exposed to viruses and security breaches) network, there is an overriding problem that IM deletion is not under the sole control of your organization. Trying to prohibit the use of IM to avoid having to manage IM does not work in the real world. The use of 3rd party IMs through, Yahoo, AOL, and Microsoft are a potential loophole to this type of IM policy because stopping their use is incredibly difficult (think about trying to control all applications on all network computers, laptops, smartphones, and PDAs) and data and journals for these IMs can also be stored on the 3rd party servers. This data can be brought in as evidence via a 3rd party subpoena. Moreover, the other parties to the IM chat, whether a co-worker from your organization or someone outside your organization, can save the IM chat thread to their local hard drive. As one very experienced and technology adept litigator friend of mine likes to say about his cases, “If there is an IM out there, we will find it, and we will get it admitted into evidence.” (This highlights issues in my next article: the too often neglected practice of scrubbing or wiping server and local hard drives so computer forensics will not be able to easily “undelete” even properly deleted IM and other electronic data. Perhaps I should title it, “Don’t Worry About Monitoring Deleted Stuff -- The Easy Route to Losing a Lawsuit or Being Invited to Club Fed.”) Based on these issues, you will be best served by an IM policy that considers realistic corporate employee IM usage and a plan for effectively managing that policy.
So the question remains: can you implement an official IM policy where all IMs are deleted immediately and avoid any IMs from becoming a part of your business records -- In effect treating them like a phone conversation that isn’t worth the paper it isn’t written on? Possibly. But here are some of the arguments against taking this approach.
Firstly, I like to refer to IMs as “Instant Emails.” This is because if you print out an IM thread, it looks pretty much just like an email thread. You can readily identify the parties, the subject matter, and the time of the messages. Pretty good to excellent foundation for having that IM or a printout of it submitted as evidence in a legal proceeding, especially when it contains critical evidence (old trial lawyer taught me a valuable lesson for litigation, never lose sight of the forest for the trees -- Judges can really bend the rules in favor of just results.) Do you think your lawyer wants to stand in front of a judge and argue that the IM thread in question, which contains critical evidence to your legal proceeding, is not admissible because it was created and kept against corporate policy? The answer is no. And as more and more of our younger attorneys come on board experienced with IM technology, and more and more judges understand the use of IMs in the workplace, this argument to exclude IMs as evidence is going to be more and more difficult to win.
Secondly, even if the content would not be considered critical, or a smoking gun, and appears only moderately negative to your case, you now have a problem because you have made it look more important than it is. If you have submitted that your policy is to immediately delete all IMs, and a printout of an IM thread is submitted based on the fact that one of your employees or a third party thought it might be important enough to warrant saving on their hard drive, it will appear like you have a sham policy which can no longer be trusted. The evidence looks more damning because you tried to delete it, and someone saved it in spite of your efforts to keep it from the trier of fact. You have now opened the door to opposing counsel or investigators making a motion to expand the scope of discovery to examine more of your electronic data in search of material reasonably likely to lead to the discovery of admissible evidence because your electronic data disclosure cannot be trusted.
It is not hard for counsel to raise this issue. One simple deposition or interrogatory will ask if the answering party knows of anyone who perhaps saves IMs or emails that are supposed to be deleted. When, under penalty of perjury, someone answers yes, the door is nudged open, and additional discovery will likely be ordered. Your usual arguments in defense of limiting expanded discovery (i.e. it is overly burdensome and too costly) could be outweighed and defeated when to the judge it looks like you have either negligently or intentionally failed to produce requested materials that you should have. In the discovery battle, or as attorneys sometimes refer to it, the war within the war, you are now in a weakened position.
Lastly, IM technology is progressing and converging towards a single ubiquitous user interface. It will become more common that a single application will handle all your email, IM, phone chat and perhaps even video chat based on a simple click of a mouse on a tab on your computer screen. So eventually your counsel might be forced to argue, “well your honor, we agree that if this employee had been having an email thread, this information would be readily admissible and we would have needed to save and produce it to the other side, but because our employee had selected the IM chat button instead of the email button, this information is not admissible.” Good luck with that argument!
Now that you better understand why you need an IM policy, even if it is to strictly limit its usage, and can recognize the many pitfalls in implementing a sound policy, I will leave you with one last bit of free and non-legal-relationship-forming advice. It is true that IMs are more difficult to manage due to the variety of 3rd party IM applications, and the lack of management software designed to handle all the different options, but there are tools available that can help with this. The important thing to keep in mind is that in order for any good electronic document plan to be effective and provide your best protection, it must be created with attention to documentation, the people responsible for maintaining it, the technology tools you will use, and, your schedule to review and test your plan on a regular basis. Is this the best approach for managing IMs? Yes. On balance, even if the standards for your document retention plan are not specifically covered by the SEC, HIPAA, Sarbanes-Oxley or other industry-specific regulations they will still be controlled by the FRCP Rule 26(f) and general state or local discovery and evidentiary rules. These frequently include balancing tests based on standards of reasonableness. Therefore, as the technology to manage IM and the rest of your electronically stored information becomes easier, faster, cheaper, and more readily adopted, it will be less reasonable and more potentially dangerous for you not to manage it in a similar fashion. The last bit of good news is that your competitors, and potential litigation adversaries, will face this same burden.
By Cary J. Calderone, Esquire
January 7, 2008
The motivation for this article occurred few weeks ago. I was sitting in the audience of a continuing legal education seminar on patent strategies. One topic that was of interest to me was a discussion of document retention policies and electronic discovery related to patents. A panelist, a senior attorney for a very large technology company, addressed email management as it related to litigation discovery. I raised my hand for clarification and asked, “When you say email, are you including instant messages in that definition or will you discuss them separately?” One of the most well regarded and experienced patent litigators in Europe, who was sitting nearby, leaned over and whispered to me, “excellent question!” The panelist however, rolled his eyes and said quickly, “we just don’t believe IMs are business records and don’t treat them as such.” My jaw dropped. According to the most recent Federal Rules of Civil Procedure (“FRCP”), instant messages certainly can and should be considered ESI “electronically stored information.” (See, FRCP Rule 26(f).) What constitutes a “Business Record” is defined by its content as well as its form and industry business practices. Current email retention policies were developed because using email to conduct business became a standard operating procedure. Similarly, use of facsimiles to create binding legal agreements developed over time. Although IM is not yet at that level of acceptance, some industries (just talk to your friendly stockbroker) already specifically track and retain IM to remain compliant with SEC and other regulations. In fact, many email applications track or “journal” instant messages in the same manner as email and in the same in-boxes.
I approached the panelist at the lunch break. He recognized me and quickly said, “maybe I misspoke.” He claimed that his company had just set a policy to not conduct any business via IM so they would not have to worry about managing or retaining IM messages for compliance and litigation purposes. This raises an important question: Is banning or severely limiting IM usage the best way to avoid having to manage it for document retention and legal discovery purposes? I don’t think so and here’s why:
IM is becoming more prevalent in research and development, marketing, sales and customer service. In fact, there are those who would argue vehemently that IM is becoming the most important business productivity tool within corporate enterprises. Perhaps you do not believe that IM is important to your organization. Here is a quick test. Have your legal department send an email to your department heads requesting comments on whether you should just discontinue or severely limit the use of all Instant Messaging applications on your corporate network given the complexity of the document retention and potential legal issues. A General Counsel I know did just that. Within 30 minutes responses indicated the regular use of 10 different IM applications, in addition to the company provided and managed application -- and that it would be very disruptive, if not impossible to prohibit IM use. These emails responses were real eye openers. Her reply was, what if we just did not have an IM policy, and we let people use whatever they desired and just told them nothing was to be used for official business and nothing should be saved. (In essence treating IM chat sessions just like a phone call, and when you hang up from a phone conversation, there is no written record.) Not even considering that the likely response from your IT director and other employees responsible for network security would want to quit their jobs rather than try to manage security for your new “open” (read exposed to viruses and security breaches) network, there is an overriding problem that IM deletion is not under the sole control of your organization. Trying to prohibit the use of IM to avoid having to manage IM does not work in the real world. The use of 3rd party IMs through, Yahoo, AOL, and Microsoft are a potential loophole to this type of IM policy because stopping their use is incredibly difficult (think about trying to control all applications on all network computers, laptops, smartphones, and PDAs) and data and journals for these IMs can also be stored on the 3rd party servers. This data can be brought in as evidence via a 3rd party subpoena. Moreover, the other parties to the IM chat, whether a co-worker from your organization or someone outside your organization, can save the IM chat thread to their local hard drive. As one very experienced and technology adept litigator friend of mine likes to say about his cases, “If there is an IM out there, we will find it, and we will get it admitted into evidence.” (This highlights issues in my next article: the too often neglected practice of scrubbing or wiping server and local hard drives so computer forensics will not be able to easily “undelete” even properly deleted IM and other electronic data. Perhaps I should title it, “Don’t Worry About Monitoring Deleted Stuff -- The Easy Route to Losing a Lawsuit or Being Invited to Club Fed.”) Based on these issues, you will be best served by an IM policy that considers realistic corporate employee IM usage and a plan for effectively managing that policy.
So the question remains: can you implement an official IM policy where all IMs are deleted immediately and avoid any IMs from becoming a part of your business records -- In effect treating them like a phone conversation that isn’t worth the paper it isn’t written on? Possibly. But here are some of the arguments against taking this approach.
Firstly, I like to refer to IMs as “Instant Emails.” This is because if you print out an IM thread, it looks pretty much just like an email thread. You can readily identify the parties, the subject matter, and the time of the messages. Pretty good to excellent foundation for having that IM or a printout of it submitted as evidence in a legal proceeding, especially when it contains critical evidence (old trial lawyer taught me a valuable lesson for litigation, never lose sight of the forest for the trees -- Judges can really bend the rules in favor of just results.) Do you think your lawyer wants to stand in front of a judge and argue that the IM thread in question, which contains critical evidence to your legal proceeding, is not admissible because it was created and kept against corporate policy? The answer is no. And as more and more of our younger attorneys come on board experienced with IM technology, and more and more judges understand the use of IMs in the workplace, this argument to exclude IMs as evidence is going to be more and more difficult to win.
Secondly, even if the content would not be considered critical, or a smoking gun, and appears only moderately negative to your case, you now have a problem because you have made it look more important than it is. If you have submitted that your policy is to immediately delete all IMs, and a printout of an IM thread is submitted based on the fact that one of your employees or a third party thought it might be important enough to warrant saving on their hard drive, it will appear like you have a sham policy which can no longer be trusted. The evidence looks more damning because you tried to delete it, and someone saved it in spite of your efforts to keep it from the trier of fact. You have now opened the door to opposing counsel or investigators making a motion to expand the scope of discovery to examine more of your electronic data in search of material reasonably likely to lead to the discovery of admissible evidence because your electronic data disclosure cannot be trusted.
It is not hard for counsel to raise this issue. One simple deposition or interrogatory will ask if the answering party knows of anyone who perhaps saves IMs or emails that are supposed to be deleted. When, under penalty of perjury, someone answers yes, the door is nudged open, and additional discovery will likely be ordered. Your usual arguments in defense of limiting expanded discovery (i.e. it is overly burdensome and too costly) could be outweighed and defeated when to the judge it looks like you have either negligently or intentionally failed to produce requested materials that you should have. In the discovery battle, or as attorneys sometimes refer to it, the war within the war, you are now in a weakened position.
Lastly, IM technology is progressing and converging towards a single ubiquitous user interface. It will become more common that a single application will handle all your email, IM, phone chat and perhaps even video chat based on a simple click of a mouse on a tab on your computer screen. So eventually your counsel might be forced to argue, “well your honor, we agree that if this employee had been having an email thread, this information would be readily admissible and we would have needed to save and produce it to the other side, but because our employee had selected the IM chat button instead of the email button, this information is not admissible.” Good luck with that argument!
Now that you better understand why you need an IM policy, even if it is to strictly limit its usage, and can recognize the many pitfalls in implementing a sound policy, I will leave you with one last bit of free and non-legal-relationship-forming advice. It is true that IMs are more difficult to manage due to the variety of 3rd party IM applications, and the lack of management software designed to handle all the different options, but there are tools available that can help with this. The important thing to keep in mind is that in order for any good electronic document plan to be effective and provide your best protection, it must be created with attention to documentation, the people responsible for maintaining it, the technology tools you will use, and, your schedule to review and test your plan on a regular basis. Is this the best approach for managing IMs? Yes. On balance, even if the standards for your document retention plan are not specifically covered by the SEC, HIPAA, Sarbanes-Oxley or other industry-specific regulations they will still be controlled by the FRCP Rule 26(f) and general state or local discovery and evidentiary rules. These frequently include balancing tests based on standards of reasonableness. Therefore, as the technology to manage IM and the rest of your electronically stored information becomes easier, faster, cheaper, and more readily adopted, it will be less reasonable and more potentially dangerous for you not to manage it in a similar fashion. The last bit of good news is that your competitors, and potential litigation adversaries, will face this same burden.
January 16, 2008
Welcome to my blog.
Company electronic data management has changed dramatically. As companies adopted technology to move from paper documents to electronic data stored on company servers, the main concerns were safekeeping their data and growing and managing their electronic "knowledge. " Now, they must actively monitor their electronic data so they will be able to comply with government regulations and the Federal Rules of Civil Procedure. Information techies used to worry about guaranteed uptime and having plenty of space to store years and years worth of emails and memos. Now, legal is making them delete the excesses as soon as practical, and lawful, so in the event they have to, they can cost-effectively search and retrieve relevant material. This blog is going to examine how the IT, legal, and other departments can work together in this new world of electronic information management.
Subscribe to:
Posts (Atom)