Spoliation & Sanctions6 min read

Metadata Spoliation: How to Preserve, Produce, and Defend ESI Integrity

By eDiscovery Expert Witness Staff·

Metadata—the hidden layer of information embedded in every electronic file—can make or break a case. When litigants fail to preserve or produce ESI in native format, they risk spoliation sanctions, authentication challenges, and evidentiary exclusion. We explain how to preserve metadata integrity, navigate Rule 37(e) obligations, and build defensible workflows that satisfy both the Federal Rules of Civil Procedure and the Federal Rules of Evidence.

Metadata Spoliation: How to Preserve, Produce, and Defend ESI Integrity — eDiscovery Expert Witness

Metadata is the DNA of electronically stored information. Every email, Word document, spreadsheet, and database record carries embedded data about its creation, modification, transmission, and storage. This information—author names, timestamps, edit histories, geolocation tags, and system identifiers—often proves more valuable than the content itself. Yet metadata remains one of the most misunderstood and frequently mishandled aspects of eDiscovery. Litigants who fail to preserve or produce metadata face spoliation motions, authentication objections, and potential Rule 37(e) sanctions. Understanding metadata obligations is no longer optional; it is foundational to competent ESI practice.

What Metadata Is and Why It Matters in Litigation

Metadata falls into three categories. Application metadata is created by the software that generates a file—author, creation date, last-modified date, and revision history in a Word document, for example. System metadata is generated by operating systems and servers—file paths, access logs, and backup timestamps. Embedded metadata includes hidden content such as tracked changes, comments, and prior versions. Each type serves distinct evidentiary purposes. Application metadata can establish authorship and timeline. System metadata can prove chain of custody and demonstrate that a file was not altered post-litigation. Embedded metadata can reveal concealed edits or collaborative drafting that contradicts a party's narrative.

The Federal Rules of Evidence require authentication under Rule 901 before ESI can be admitted. Metadata provides the foundational showing that a document is what its proponent claims. Rule 902(13) and 902(14) permit self-authentication of ESI through certificates or affidavits describing the process used to collect and preserve electronic records. Without intact metadata, counsel may struggle to meet these thresholds, and opposing parties will exploit gaps to challenge admissibility.

Rule 26 and the Duty to Preserve Metadata

Rule 26(f) requires parties to confer early about ESI issues, including the form of production. The rule contemplates that parties will discuss whether to produce documents in native format, near-native format such as TIFF with metadata load files, or as static PDFs. The Sedona Conference Cooperation Proclamation and Commentary on Rule 26(f) emphasize that counsel should address metadata preservation and production formats before discovery begins. Waiting until a dispute arises invites motion practice and judicial intervention.

Rule 34(b)(2)(E) permits a requesting party to specify the form of production. If no form is specified, Rule 34(b)(2)(E) requires production in the form in which ESI is ordinarily maintained or in a reasonably usable form. For most ESI, ordinary maintenance means native format with metadata intact. Converting files to PDF or printing emails to paper destroys metadata and may constitute spoliation if done after the duty to preserve attaches. The duty to preserve arises when litigation is reasonably anticipated, and it extends to all relevant ESI, including metadata that may support or undermine claims or defenses.

Rule 37(e) and Metadata Spoliation Sanctions

Rule 37(e) governs sanctions for failure to preserve ESI. The rule establishes a two-tier framework. If a party fails to preserve ESI that cannot be restored or replaced through additional discovery, the court may order measures no greater than necessary to cure the prejudice, but only upon a finding that the losing party acted with intent to deprive another party of the information's use in litigation. Metadata spoliation frequently triggers Rule 37(e) analysis because metadata is often unique and irreplaceable. Once a file is converted to PDF or printed, the original metadata may be lost forever.

Courts examine whether the spoliating party took reasonable steps to preserve ESI. The EDRM Information Governance Reference Model and Sedona Principle 6 make clear that preservation obligations require suspending routine deletion policies and implementing litigation holds. For metadata, reasonable steps include collecting files in native format, using forensically sound tools, and avoiding actions that alter timestamps or embedded data. Counsel who instruct clients to forward emails rather than export them from the mail server, or who permit IT staff to copy files without preserving system metadata, create spoliation risk.

Intentional vs. Negligent Metadata Loss

Rule 37(e)(2) permits severe sanctions—adverse inference instructions, dismissal, or default judgment—only when the court finds that a party acted with intent to deprive another party of the information's use. Intent is difficult to prove, but courts infer it from conduct such as deleting files after receiving a preservation notice, instructing employees to avoid creating records, or using software designed to strip metadata. Even absent intent, Rule 37(e)(1) authorizes curative measures if prejudice results. These may include additional discovery, cost-shifting, or evidentiary preclusion. The lesson is clear: metadata loss, whether intentional or negligent, exposes litigants to sanctions and strategic disadvantage.

Defensible Metadata Preservation Workflows

A defensible metadata preservation workflow begins the moment litigation is reasonably anticipated. Counsel should immediately issue a litigation hold that identifies custodians, data sources, and file types. The hold must instruct custodians not to delete, alter, or convert files. IT personnel should be directed to suspend auto-delete policies, disable overwrite functions, and halt any processes that modify metadata, such as migration projects or system upgrades.

Collection must use forensically sound methods. Forensic imaging creates bit-by-bit copies of storage media, preserving all metadata and ensuring that original files remain unaltered. For cloud-based ESI such as Microsoft 365 or Slack, native export tools should be used rather than manual downloads or screenshots. Chain of custody documentation should record who collected the data, when, using what tools, and where the data is stored. The EDRM Preservation and Collection stages provide detailed guidance on maintaining metadata integrity throughout these steps.

Production Format and Metadata Load Files

When producing ESI, parties should produce native files whenever possible. Native production preserves all metadata and allows the receiving party to search, sort, and analyze files as they existed in the producing party's systems. If native production is impractical—due to volume, privilege redactions, or confidentiality concerns—near-native formats such as TIFF images with accompanying metadata load files offer a compromise. Load files, typically in DAT or CSV format, contain extracted metadata fields such as author, date sent, recipients, and file paths. The Sedona Conference Best Practices Commentary on the Production of ESI recommends that parties agree on metadata fields to be produced and document those agreements in Rule 26(f) reports or protective orders.

Authentication Challenges and FRE 901 Compliance

Metadata is both a tool for authentication and a target for challenge. Under Rule 901(b)(4), a document can be authenticated by its appearance, contents, substance, and internal patterns, including metadata. An email's header data, showing sender, recipient, and transmission route, can establish that the message is what it purports to be. A spreadsheet's edit log can prove that a particular user made changes on a specific date.

However, metadata is not self-proving. Opposing counsel will challenge metadata authenticity if the producing party cannot demonstrate a reliable chain of custody or if forensic analysis reveals anomalies. Rule 902(13) and 902(14) permit self-authentication through a qualified person's certification, but the certification must describe the process used to create, collect, and preserve the record. Courts applying Daubert and Rule 702 standards scrutinize expert testimony about metadata, requiring that the expert's methods be scientifically valid and reliably applied. Experts must be prepared to explain hash-value verification, forensic-tool validation, and metadata extraction protocols.

Common Metadata Pitfalls and How to Avoid Them

  • Forwarding emails instead of exporting from the server, which changes the sent date and creates new metadata.
  • Using 'Save As' or copy-paste functions that alter creation and modification timestamps.
  • Converting native files to PDF without preserving metadata in a separate load file.
  • Allowing custodians to self-collect ESI without IT oversight or forensic tools.
  • Failing to document the collection process, making it impossible to authenticate metadata later.
  • Ignoring embedded metadata such as tracked changes or comments that may be discoverable.

Each of these missteps can be avoided with proper training, clear litigation-hold instructions, and engagement of qualified eDiscovery professionals. The investment in defensible workflows pays dividends by reducing motion practice, avoiding sanctions, and strengthening the evidentiary foundation for key documents.

The Bottom Line: Metadata Is Evidence, Not an Afterthought

Metadata is not a technical detail to be delegated and forgotten. It is evidence, and the Federal Rules treat it as such. Rule 26 requires early discussion of metadata preservation and production. Rule 34 presumes native-format production unless otherwise specified. Rule 37(e) imposes sanctions for failure to preserve. Rules 901 and 902 demand authentication. Counsel who ignore metadata risk spoliation sanctions, evidentiary exclusion, and loss of credibility before the court.

Building a defensible metadata practice requires collaboration among counsel, clients, IT staff, and eDiscovery vendors. It requires early action, forensically sound tools, and meticulous documentation. Most importantly, it requires recognizing that metadata is not overhead—it is the foundation of ESI authenticity and admissibility. Litigators who master metadata preservation and production gain a strategic advantage. Those who neglect it face consequences that no amount of after-the-fact explanation can cure. If your team needs guidance on metadata workflows, spoliation defense, or expert support for authentication challenges, our contact page is the place to start the conversation.

Retain the Expert

ESI is the fight in your matter?

Daniel B. Garrie has served as an eDiscovery expert, Special Master, and discovery referee in 100+ courts and tribunals nationwide. Send the matter name, jurisdiction, and key dates for a prompt conflict check and a scoping conversation.