An ESI protocol is usually five to fifteen pages long, arrives as a redline three days before a scheduling conference, and gets signed by someone who has never seen the client's data. Six months later it is the document opposing counsel quotes back at you when they demand a re-production, and the document the court reads when you argue that a request is disproportionate. Almost nothing else in discovery has that ratio of attention paid to consequence produced.

The Rule 26(f) conference is where the topics get raised. The protocol is where they get fixed. This article is about the second half of that: the individual clauses, what each one actually obligates you to do, and what the wrong version costs.

Why the protocol outlives the negotiation

Two features make an ESI protocol unusually durable. It is normally entered as a stipulated order, so changing it later requires your adversary's consent or a motion, and your adversary has no reason to consent to a term currently working against you. And its obligations are operational: a protocol specifying TIFF images with a defined metadata load file does not describe a preference, it sets the processing specification your vendor bills against for the life of the case.

The practical test for every clause is the same. Assume the case goes badly: volumes triple, a custodian turns out to have used a messaging app nobody mapped, and the other side becomes difficult. Read the clause again in that world. If it still works, sign it.

Key takeaway

Model the consequences of each clause against a bad version of your own case before you agree to it. Most protocol disasters are terms that were reasonable under the volume everyone assumed at the scheduling conference.

Scope and custodian identification

Custodian count is the single most expensive number in the document. Everything downstream scales off it: collection hours, processing volume, hosting, review population, privilege review, and the size of the log. A protocol that names twenty-two custodians has priced the case, whatever the rest of it says.

The mistake is agreeing to a fixed list too early, before anyone has run a data-volume assessment. The better structure is a named starting set plus a defined mechanism for adding to it — a written request identifying the proposed custodian and the basis for believing they hold unique relevant material, a stated period to respond, and a burden-shift so that the requesting party carries the argument on a disputed addition. That gives the other side a real path to more custodians while making each addition a considered decision rather than an assumption.

Watch the phrasing of the scope clause itself. "All ESI in the possession, custody, or control of the responding party" is not a scope definition; it is a restatement of Rule 34 that gives away the proportionality argument you will need later. Tie scope to identified custodians, identified sources, and a date range, and say plainly that anything outside those bounds is addressed by agreement or by motion.

Date ranges

Date ranges are negotiated as if they were symmetrical, and they rarely are. A range that reaches back before a migration means restoring data from a legacy system with different metadata, different export tooling, and different costs. Before agreeing to a start date, ask IT one question: what changed in our environment during this window? Migrations, tenant consolidations, retention-policy changes, and acquisitions all sit invisibly inside a date range until someone tries to collect across one.

Sources in scope, sources out

The sources clause is where modern collaboration data either gets handled deliberately or gets handled by default. Email and file shares are easy; nobody argues about them. The clauses that matter cover chat and channel messages, meeting artifacts, cloud-linked documents, mobile messages, ticketing and CRM systems, and structured databases where the relevant output is a report rather than a document.

Two drafting points are worth more than the rest of the clause combined.

Hyperlinked content. In a cloud-native environment, a large share of what used to be attachments are now links to a document that lives elsewhere and keeps changing. If the protocol's family-relationship language says "attachments," it does not reach linked content, and the parties will find that out during a deposition. Decide the question in the protocol: are linked documents collected and produced, are they produced only on targeted request, and if produced, is it the version as of the message date or the current version? Every answer is defensible. Silence is not, because silence means arguing about it later at your own cost.

Non-party and employee-owned devices. A protocol that quietly extends to personal devices under a bring-your-own-device policy has committed you to a collection exercise involving employment counsel, privacy notices, and consent. That may be the right answer, but it should be a decision, not an inheritance from a form.

The "not reasonably accessible" designation

Rule 26(b)(2)(B) lets a responding party decline to produce ESI from sources it identifies as not reasonably accessible because of undue burden or cost. The designation is not self-executing. If the requesting party moves to compel, you carry the burden of showing inaccessibility, and even then the court can order production for good cause.

What this means for the protocol is narrow and important: get the identification obligation into the document, with a deadline and a defined level of detail. A clause requiring each party to identify not-reasonably-accessible sources by system, with a summary of the burden, within a set number of days after entry protects both sides. It stops the requesting party discovering a withheld source in a deposition, and it stops the responding party from having to justify a designation it made informally in an email eight months earlier. Backup tapes, decommissioned systems, legacy archives, and anything requiring restoration to a working environment belong in that identification.

Search methodology

Three structures are common, and they carry very different obligations.

  • Negotiated search terms. Predictable and easy to explain, but you inherit whatever the terms return. Terms are agreed on a guess about the corpus, and a single common surname or product code can multiply the review population.
  • Technology-assisted review. Cheaper at volume, and now uncontroversial. Moore v. Publicis Groupe, 287 F.R.D. 182 (S.D.N.Y. 2012), is generally described as the first opinion approving computer-assisted review; the court framed the real inquiry as "the process used and the interaction of man and machine that the courts needs to examine."
  • Terms first, then TAR. The most common approach in practice, and the one most often under-specified, because the protocol describes the terms in detail and the review technology in a sentence.

If you negotiate search terms, negotiate the right to test them. A clause permitting each side to run hit counts and propose revisions before the terms are locked, with a stated number of iterations, converts an argument about burden into an arithmetic exercise. Hit reports showing that one proposed term returns several hundred thousand documents with families are more persuasive than any adjective.

If you use TAR or continuous active learning, the negotiation is really about disclosure and validation. In Moore, the producing party volunteered an unusual degree of transparency, agreeing to show its seed set including documents coded non-relevant, and the court recommended that counsel in future cases be willing at least to discuss that. Practice since has not settled how much disclosure is standard. What has settled is that a protocol should say what validation looks like: a statistically defensible sample, a stated measure, and a stated point at which review stops. Agreeing to "industry standard validation" with no definition means agreeing to whichever definition your adversary produces when it suits them.

Form of production

Rule 34(b)(2)(E) supplies a default: absent a specified form, produce ESI as it is ordinarily maintained or in a reasonably usable form, and no party need produce the same ESI in more than one form. The protocol displaces that default, which is why the form clause is worth reading twice.

The disagreement is nearly always native production versus TIFF images with a load file. Native preserves the working document and its metadata; images give you a stable Bates number, clean redaction, and a predictable page count. Most protocols land on a hybrid: images plus load file for most types, native for spreadsheets, presentations, audio, video, and anything with dynamic content.

Whatever the split, the clause has to answer four questions. Which metadata fields travel with the production, listed by name rather than by reference to a category. How family relationships are preserved and identified in the load file. How redactions are applied — and, critically, what happens to the native file of a redacted document, since producing a redacted image alongside an unredacted native defeats the redaction. And what "reasonably usable" means for chat data, which has no native page and no obvious document boundary.

Courts do resolve these disputes, and not always in the requesting party's favour. In In re State Farm Lloyds, 520 S.W.3d 595 (Tex. 2017), homeowners sought native production for the metadata; the insurer offered searchable static images consistent with how it processed claims in the ordinary course. Applying the Texas discovery rules, the court held the dispute was governed by proportionality rather than the requesting party's preference, observing that metadata's relevance "must be obvious or at least linked, more or less concretely, to a claim or defense" and that hypothetical needs deserve no weight. The rules differ from the federal ones, but the reasoning travels: form of production is a proportionality question, and it is far cheaper to win it in the protocol than in motion practice after a production has already been made.

  1. Except as provided below, documents will be produced as single-page black-and-white Group IV TIFF images at 300 DPI, with document-level extracted text where available and OCR text where not, accompanied by a delimited load file and an image cross-reference file.
  2. Spreadsheets, presentations, audio files, video files, computer-aided design files, and files whose content is not reasonably represented as a static image will be produced in native format with a single-page placeholder image bearing the production number and any confidentiality designation.
  3. Each production will include the metadata fields listed in Appendix A to the extent those fields exist in the source data and are reasonably available from the processing tool. Neither party is required to create, populate, or manually code a metadata field that does not exist in the source data.
  4. Family relationships will be preserved. Each record will identify its family group, its parent record, and the range of its children, whether the relationship arises from an attachment or from a document linked in the body of a message. Where a linked document is produced, the version produced will be the version in effect on the date of the message that links to it, where that version is reasonably available.
  5. Documents produced with redactions will be produced as images only, with the corresponding text and any metadata field whose content would disclose the redacted material withheld or itself redacted. A document produced in redacted form will not also be produced in native format.

De-duplication and threading

De-duplication is usually one line, and that one line decides how much of the case gets reviewed twice. Global de-duplication across all custodians produces the smallest population and the lowest cost. Custodial de-duplication, where a document is retained once per custodian, produces a larger population but preserves the custodian-by-custodian picture of who held what — which matters when possession is itself an issue.

Choose global de-duplication if you can, but only with a companion clause requiring that all custodians of a de-duplicated document be identified in a designated metadata field. Without it, you have destroyed the "who had this" evidence and will be asked to reproduce.

Email threading is a separate lever and a bigger one. Producing only the most inclusive message in a thread removes an enormous share of redundant review. Say explicitly whether threading is used for review only or also for production, because those are different agreements. Suppressing less-inclusive messages from production is defensible if the protocol says so and if branched threads and unique attachments are handled; doing it silently is a re-production waiting to happen.

Privilege logging

Rule 26(b)(5)(A) requires a party withholding privileged material to describe the nature of what is withheld in a way that lets the other parties assess the claim. It does not require a document-by-document log — that is convention, and convention is negotiable.

Categorical logging, where privileged documents are grouped by category with a description of each group, is dramatically cheaper on a large population and is regularly agreed to. Negotiate for it, and negotiate the exclusions that come with it in the same clause: communications with outside counsel after the complaint date are typically excluded from logging entirely, and duplicate privileged documents within a logged family usually should be too.

Treat the logging deadline as a substantive term rather than a scheduling detail. SEC v. Yorkville Advisors, LLC, 300 F.R.D. 152 (S.D.N.Y. 2014), is the case to read before you agree to a date you cannot meet. The court found the logs so lacking in detail that they did not permit an intelligent assessment of whether the privileges were validly asserted, refused to credit a revised log served a year later as untimely, and held that the party's unjustified failure to serve proper indices in a timely manner operated as a waiver of the privileges claimed. That is the entire risk in one sentence: an inadequate log can cost you the privilege itself.

The logging clause also interacts with your clawback protection. An FRE 502(d) order addresses waiver by inadvertent disclosure. It does not address waiver by inadequate logging, which is a different failure with the same consequence. You need both.

Deadlines, rolling productions, and disputes

Rolling production is standard and sensible, and it is where schedules quietly break. A clause committing to "substantial completion" by a date, without defining the term, converts a status report into a dispute. Define it: substantial completion means production of all documents identified as responsive from the agreed custodians and sources through the agreed methodology, excluding a stated category of stragglers, and say what those stragglers are.

Include a dispute-resolution clause, and make it cheap. A short meet-and-confer requirement, followed by a joint letter of a stated page limit rather than full briefing, resolves most protocol disputes in weeks instead of months. Many judges prefer it. The clause costs nothing to agree to at the outset and is nearly impossible to obtain once the parties are already fighting.

Clawback: point to an order, not to an agreement

Most ESI protocols contain a clawback paragraph. Many of those paragraphs are worth considerably less than the parties believe, because FRE 502(e) provides that an agreement about the effect of disclosure binds only the parties to the agreement unless it is incorporated into a court order. A clawback clause negotiated between counsel and never entered does nothing about a co-defendant, a later plaintiff, a state-court adversary, or a regulator.

The fix is structural. Keep the clawback mechanics in the protocol, and have the substantive non-waiver protection live in an entered FRE 502(d) order that the protocol references.

  1. The non-waiver protections applicable to disclosures in this action are set out in the Court's Order under Federal Rule of Evidence 502(d) entered at Dkt. No. ___, which governs and controls over any inconsistent provision of this Protocol.
  2. Nothing in this Protocol limits, conditions, or qualifies that Order. In particular, no party's compliance or non-compliance with any provision of this Protocol, and no decision by a party to conduct, limit, or forgo a privilege review before production, bears on whether a disclosure results in waiver.
  3. A producing party may assert a claim of privilege over produced material at any time by written notice identifying the material by production number. Notice is effective on service and need not be accompanied by a privilege log; the producing party will log the clawed-back material within fourteen days.

Read your current form protocol against that structure. If its clawback paragraph stands alone, uses the word "inadvertent" repeatedly, or requires the producing party to have taken reasonable steps, it is a 502(e) agreement wearing a 502(d) label, and it will be argued that way.

What to do before the next one arrives

The clauses above are not equally contestable. Form of production and de-duplication are technical and usually settle quickly. Custodian scope, search methodology, privilege logging, and the clawback structure are where the money and the risk are, and they are the four you should never negotiate on someone else's paper.

The organizations that do this well have a standing protocol of their own, drafted when nobody was under deadline, reflecting how their systems actually export data and which metadata fields their environment actually produces. Maintaining one as part of a playbook, alongside a current map of your data sources, means that when the redline arrives three days before the conference, you are comparing it to a considered position rather than drafting one at speed. That is the difference between negotiating a protocol and receiving one.