Knowledge HubeDiscovery › Article 001
eDiscovery Certification Council Knowledge Hub

What Is eDiscovery?

A practical introduction to electronic discovery — from electronically stored information to defensible evidence.

Article 001eDiscoveryVendor-neutralReviewed August 2026

What is eDiscovery?

In one sentence, eDiscovery is the process of identifying, preserving, collecting, processing, reviewing, analysing and producing electronically stored information that may be relevant to litigation, investigations, regulatory proceedings or similar legal matters.

That definition is simple enough. The work behind it often is not. A dispute that once involved several filing cabinets of correspondence may now involve millions of emails, Microsoft Teams conversations, Slack messages, mobile-phone data, spreadsheets, databases, cloud documents, photographs, audio recordings and information held inside specialist business applications.

Finding the information is only part of the problem. It may also need to be preserved properly, collected without unnecessarily compromising its integrity, reduced to a manageable population, searched and reviewed, assessed for relevance and privilege, and ultimately produced in an appropriate form. That combination of law, technology, information management and investigative technique is what makes eDiscovery a distinct professional discipline.

ISO/IEC 27050-1:2019 describes electronic discovery as the process of discovering pertinent electronically stored information (ESI) or data in an investigation, litigation or similar proceeding. It identifies concepts including identification, preservation, collection, processing, review, analysis and production.

Why does eDiscovery exist?

The simplest answer is that evidence has changed. Business communication and record-keeping are now overwhelmingly digital. A commercial decision may be documented not in a single letter but across an email chain, a Teams meeting, several instant messages, an Excel workbook, a CRM entry and documents stored in SharePoint or another cloud platform.

Electronic information creates opportunities that did not exist with paper evidence. It can contain metadata, searchable text and relationships between people, events and documents that help reconstruct what happened. It also creates scale and complexity.

The practical challenge is to find the information that matters without losing important evidence, collecting far more than is necessary, overlooking relevant material or making the exercise disproportionately expensive.

The eDiscovery lifecycle at a glance

The EDRM is widely used as a conceptual model. It is not a rigid waterfall: stages can overlap, repeat and move backwards as understanding develops.

Information Governance → Identification → Preservation → Collection → Processing → Review → Analysis → Production → Presentation.

eDiscovery, eDisclosure and electronic evidence

Terminology varies between jurisdictions. eDiscovery is particularly common in the United States and has become a widely used international industry term. In England and Wales, practitioners commonly encounter electronic disclosure or eDisclosure.

The operational disciplines overlap substantially, but the legal rules governing scope, preservation, searching and disclosure differ between jurisdictions. eDiscovery should therefore never be treated as a technology process divorced from the applicable legal framework.

Electronic evidence is related but not identical. Electronic evidence is digital information capable of having evidential value. eDiscovery is the broader process through which potentially relevant electronic information may be identified, preserved, collected, examined, reviewed and produced.

What is ESI?

ESI means electronically stored information. It is much broader than ordinary electronic documents. It can include email, office documents, databases, Teams and Slack content, mobile data, cloud and SaaS data, social media, audio and video, metadata, AI-generated content, system records and web content.

Modern evidence may have no meaningful paper equivalent. A Teams conversation can include messages, reactions, edits and links to files that later change. A screenshot may show the words while failing to preserve the context that gives them meaning.

How does the eDiscovery process work?

Information governance. Good eDiscovery often begins before litigation. Organisations need to understand what information they create, why they retain it, where it is stored and when it should legitimately be deleted.

Identification. The team determines where potentially relevant information may exist. That may include custodians, email systems, laptops, mobile devices, shared drives, cloud storage, collaboration platforms, databases, archives and business applications.

Preservation. Potentially relevant information may need protection from alteration or destruction. Measures can include legal holds, suspension of routine deletion, in-place preservation in cloud platforms, forensic preservation or other steps suited to the source and the matter.

Collection. Data is gathered from identified sources using methods appropriate to the legal and evidential needs. A targeted logical collection may be sufficient in one matter; another may require forensic acquisition.

Processing. Collected data is prepared for searching, analysis and review. Processing may include extracting text and metadata, expanding container files, identifying file types, deduplicating, filtering, performing OCR and managing exceptions.

Review. Lawyers, investigators or trained reviewers assess material for relevance or responsiveness, privilege, confidentiality, issue coding, privacy and redaction. Email threading, near-duplicate detection, TAR and machine learning can reduce repetitive work and help prioritise material.

Analysis. Analysis looks across the collection for patterns, people, topics, timelines and relationships.

Production. Responsive information is prepared and delivered to another party, regulator or authority in the required format. Quality control matters.

Presentation. Electronic evidence may ultimately be displayed in interviews, depositions, hearings, trials or other proceedings.

A simple example of eDiscovery in practice

Suppose a company dismisses a senior sales executive. Six months later, the executive alleges that the stated reason for dismissal was false. Relevant information could include emails, Teams messages, HR-system records, Word documents, calendar entries and messages on a company mobile phone.

Simply searching the former employee’s mailbox for the word “dismissal” is unlikely to tell the whole story. The investigation may identify the relevant people and systems, preserve selected information, collect and process it, and use search terms, dates and analytics to reduce the population.

Perhaps the most significant evidence does not contain the word “dismissal” at all. Finding documents is not the same as finding evidence. Context matters.

Who is involved in eDiscovery?

Lawyers define legal scope, relevance, privilege, disclosure obligations and strategy. eDiscovery specialists translate legal requirements into defensible technical workflows. Project managers coordinate scope, deadlines, budgets, vendors, risks and reporting. Digital forensic practitioners acquire and examine devices or systems where forensic integrity and artefacts matter.

Review teams assess documents for responsiveness, privilege, issues, confidentiality and redaction. IT and information-governance professionals identify systems, retention settings, access routes and data ownership. Privacy specialists address personal data, cross-border issues, minimisation and confidentiality. Data and AI specialists support analytics, automation, machine learning and AI-assisted workflows.

What technology is used in eDiscovery?

There is no single piece of software called eDiscovery. The technology ecosystem includes tools for legal hold management, collection, forensic acquisition, processing, hosting, search, document review, analytics, TAR, redaction, production and reporting.

Large platforms may combine many functions. Specialist tools may perform one particular task exceptionally well. Technology selection should normally follow the problem rather than precede it.

Why metadata matters

Metadata can contain creation and modification information, sender and recipient details, timestamps, document properties, file paths and other system or application characteristics. Sometimes that information is simply useful for organising data; sometimes it becomes evidence itself.

Two visually identical files may have different histories. An email attachment may need to remain associated with its parent message. Careless handling of electronic information can therefore change information that is not immediately visible.

eDiscovery is not the same as digital forensics

eDiscovery often manages large populations of potentially relevant information and centres on legal discovery or disclosure, review and production. Digital forensics often examines devices, systems and artefacts in forensic depth, with greater emphasis on acquisition, examination, reconstruction and evidential integrity.

The disciplines overlap substantially and are often required in the same matter. Knowing when forensic depth is necessary — and when a proportionate eDiscovery collection is sufficient — is part of sound professional judgement.

Common eDiscovery mistakes

Starting too late; scoping only obvious custodians; collecting too much without a clear reason or too little because assumptions were never tested; failing to preserve useful metadata or relationships; using search terms or analytics without validation; treating technology as a substitute for professional judgement; failing to document material decisions; and refusing to revisit early assumptions when new evidence changes the picture.

What makes an eDiscovery process defensible?

A defensible process is better understood as one in which important decisions are reasonable, proportionate, explainable and appropriately documented.

Teams should be able to explain why custodians and date ranges were selected, why one collection method was chosen over another, how searches or TAR workflows were tested, and what quality-control measures were performed before production.

Professional judgement is unavoidable; the goal is not perfection at any cost, but a reliable process appropriate to the circumstances.

How AI is changing eDiscovery

Artificial intelligence in eDiscovery did not begin with generative AI. Machine learning has been used for years in predictive coding and Technology-Assisted Review. Continuous Active Learning can use reviewer decisions to reprioritise documents so potentially relevant material is surfaced earlier.

Generative AI broadens the possibilities. Systems can assist with document summarisation, issue identification, chronology building, conversation analysis and classification. The harder questions concern validation, human oversight, confidentiality, explainability, bias, governance and the level of reliance appropriate to a particular task.

eDiscovery in the United States and eDisclosure in England and Wales

Professionals working internationally should resist assuming that one country’s discovery rules apply everywhere. US discovery practice and English disclosure practice share many technologies and operational techniques, but their legal frameworks and terminology differ.

Technical capability does not determine legal scope. The fact that technology can search ten million documents does not mean ten million documents ought to be searched.

What skills does an eDiscovery professional need?

There is no single route into the profession. People arrive from law, litigation support, digital forensics, IT, information governance, project management, data analysis and increasingly AI and software engineering.

A strong eDiscovery specialist regularly translates between legal and technical worlds. A lawyer need not become a forensic engineer, and a technologist need not become a litigation solicitor, but each needs enough understanding of the other’s domain to recognise when a decision has legal, technical or evidential consequences.

Where is eDiscovery used?

Litigation remains its most familiar setting, but eDiscovery methods are also used in regulatory investigations, internal investigations, competition and antitrust matters, fraud investigations, employment disputes, arbitration, public inquiries, data-breach investigations and other situations where large quantities of electronic information must be examined systematically.

The most important thing to understand about eDiscovery

At its heart, eDiscovery is about finding and managing evidence in a world where human activity leaves enormous and complicated digital trails.

Technology makes it possible to deal with volumes of information that would otherwise be unmanageable. But the difficult questions remain human ones: What are we looking for? Where is it likely to exist? What must be preserved? What can reasonably be excluded? What does this document mean in context? How confident are we that important evidence has not been missed? Can we explain what we did if the process is challenged?

Practitioner takeaways

  • Start with the legal and factual problem, not the software.
  • Map people and data sources early; modern evidence is distributed across systems.
  • Preserve proportionately, but do not delay when deletion or change is a real risk.
  • Treat metadata and context as part of the evidence, not as technical decoration.
  • Use analytics and AI to improve the workflow, then validate the results.
  • Document material decisions so the process can be explained later.
  • Expect iteration. New facts often require earlier assumptions to be revisited.

Related eDiscovery Certification Council Knowledge Hub reading

Authoritative reference points

This is a vendor-neutral professional reference from the eDiscovery Certification Council Knowledge Hub. Jurisdiction-specific legal requirements should be checked against the current applicable rules and authoritative guidance.