BYOD Discovery: Preserving and Collecting ESI From Personal Devices Without Overreach
Bring-your-own-device policies put company communications on phones and laptops the company does not own or control. When litigation hits, that ownership gap does not shrink the preservation duty — it just makes compliance harder to prove.
Bring-your-own-device (BYOD) arrangements are now routine: employees text clients from personal phones, draft on personal laptops, and sync work email to devices the company neither owns nor administers. None of that changes the scope of the preservation duty. Once litigation is reasonably anticipated, the duty attaches to relevant, discoverable information wherever it lives, and a party cannot narrow that duty simply by pointing to who holds title to the hardware. The practical problem is not whether BYOD data is discoverable — it is how to preserve, collect, and produce it without triggering privacy objections, cost fights, or a spoliation motion under Rule 37(e).
Why BYOD Complicates the Preservation Duty
A legal hold notice that lists only company-issued laptops and the corporate email domain misses the point if key custodians conduct business on personal devices. Courts assess preservation adequacy by asking whether a party took reasonable steps to preserve information it had a duty to preserve, not by asking who technically owns the storage medium. A hold that ignores personal devices used for business purposes leaves an obvious gap that opposing counsel will probe at deposition, and a gap discovered after data has been lost or overwritten invites sanctions analysis. Building a defensible legal hold process from the outset — one that asks custodians directly whether they use personal devices for work communications — closes that gap before it becomes a discovery dispute.
The Loss-of-Control Problem
Personal devices are replaced, sold, or handed to family members without the company's knowledge. Messaging apps auto-delete. Cloud backups sync selectively. None of this excuses the failure to act once a duty to preserve exists; it simply means the preservation instruction has to be specific enough that a custodian understands exactly what to stop deleting and how to segregate it, and it has to be documented so counsel can show the steps taken if the data is later unavailable.
Scoping Collection Under the Proportionality Framework
Discovery is limited to matters relevant to a claim or defense and proportional to the needs of the case, considering the importance of the issues, the amount in controversy, and the parties' relative access to relevant information. That proportionality standard is the primary tool for keeping BYOD discovery bounded — it justifies collecting only the applications, date ranges, and content types that actually relate to the dispute rather than imaging an entire personal phone. A party seeking BYOD discovery should be prepared to show why a targeted collection is insufficient before demanding a full forensic image, and a party resisting broad BYOD requests should be prepared to propose a narrower, defensible alternative rather than simply objecting.
Negotiating the ESI Protocol for Personal Devices
The conference of the parties required early in a case is the right forum to address BYOD issues before they become motion practice. An ESI protocol that anticipates personal devices should specify which custodians used them for business purposes, what applications are in scope, how remote or self-collection will be validated, and what format productions will take under the rule governing production of documents and electronically stored information. Addressing this at the outset avoids a later argument that a party withheld personal-device data because the requesting party never asked for it by name.
Self-Collection Versus Forensic Collection
Custodian self-collection from a personal device — forwarding relevant texts or exporting a chat log — is faster and less invasive, but it is also harder to defend if completeness or authenticity is later challenged. Forensic collection using validated tools preserves metadata and creates a verifiable record of what was captured and when, which matters if the data is later offered as evidence and must satisfy the requirements for authentication. The choice between the two approaches should track the stakes of the case and the credibility of the custodian, not default reflexively to the cheaper option.
Privacy, Segregation, and Practical Limits
Employees have legitimate privacy interests in personal photos, health information, financial accounts, and family communications stored on the same device as work messages. A collection approach that respects proportionality also has to respect that boundary, using application-specific or keyword-bounded collection rather than a full device image whenever a narrower method will capture what discovery actually requires. Sedona Conference commentary on proportionality and cooperation supports resolving these tensions through negotiated protocols rather than unilateral positions on either side.
Chain of Custody and Authentication Exposure
Data pulled from a personal device faces the same authentication hurdles as any other ESI, and often more, because the device was never under the company's administrative control. A production that cannot show who collected the data, how, and when invites a challenge to its authenticity under the evidentiary rule requiring evidence sufficient to support a finding that the item is what it is claimed to be. Establishing and documenting chain of custody at the moment of collection — not after a dispute arises — is the difference between admissible evidence and a fight over foundation.
A Practical Checklist for BYOD Discovery
- Identify at intake which custodians use personal devices for work communications, including messaging apps outside the corporate email system.
- Extend the legal hold in writing to those devices, naming specific applications rather than relying on general language.
- Negotiate device scope, date ranges, and format into the ESI protocol before collection begins.
- Choose self-collection or forensic imaging based on the stakes of the case and the reliability of the custodian.
- Document chain of custody at the point of collection, including tool, method, and hash values where applicable.
- Segregate personal content from responsive material before review to reduce privacy exposure and review cost.
None of these steps requires exotic technology. What they require is treating personal devices as a foreseeable category of discoverable ESI from the moment a hold issues, rather than as an afterthought once opposing counsel asks a pointed deposition question about a custodian's phone.
Bottom Line
BYOD discovery sits at the intersection of preservation duty, proportionality, and privacy, and getting the scope wrong in either direction — too broad or too narrow — creates real exposure. For matters where personal-device data is contested or a preservation gap has already surfaced, a conversation with a technical expert who can help scope collection and defend the resulting record is worth having early. Reach out through the firm's contact page to discuss a specific matter.
Retain the Expert
Is ESI the fight in your matter?
Daniel B. Garrie has served as an eDiscovery expert witness, Special Master, and discovery referee in 100+ courts and tribunals nationwide. Send the matter name, jurisdiction, and key dates for a conflict check and a scoping conversation.
Not ready to retain? Track the case law instead.
The ESI Docket — a short bi-weekly digest of the eDiscovery and ESI decisions that actually change how litigators preserve, collect, and produce. No pitches.