Knowledge HubeDiscovery › Article 004
eDiscovery Certification Council Knowledge Hub

What Is ESI? Electronically Stored Information Explained

A clear guide to ESI, the forms it takes, why context and metadata matter, and why modern discovery is broader than documents.

Article 004eDiscoveryVendor-neutralReviewed August 2026

ESI in plain English

ESI means electronically stored information. In eDiscovery, the term is intentionally broad because relevant evidence may exist in almost any digital system capable of storing information. Email and office documents are only the beginning.

Common forms of ESI

Typical sources include email, Word documents, PDFs, spreadsheets, presentations, databases, shared drives, cloud storage, Teams and Slack messages, text messages, mobile applications, photographs, audio, video, social-media content, websites, system logs and business applications. Increasingly, prompts, outputs and records created through AI-enabled systems may also require consideration.

Why ‘information’ matters more than ‘file’

A file is an easy mental model, but much modern ESI is not file-based. A database record may be assembled dynamically from multiple tables. A chat message may have reactions, edits and replies. A cloud document may have versions and sharing history. Treating these as ordinary files can strip away context.

Structured, semi-structured and unstructured data

Unstructured data includes documents and free text. Structured data sits in defined fields and tables, such as transaction databases. Semi-structured data includes formats such as email or JSON that contain identifiable fields but do not behave like a conventional database. Each type can require a different collection and review strategy.

Metadata

Metadata is information about information. It can include sender, recipient, timestamps, file names, paths, authors, creation dates, modification dates, message IDs, application fields and other properties. Some metadata is essential to search and organisation; some may become evidence in its own right.

Modern collaboration data

Teams, Slack and similar platforms challenge document-centric thinking. A conversation can span channels, threads, direct messages, reactions, attachments and linked cloud files. Messages may be edited or deleted. The evidential unit may therefore be a conversation in context rather than a single message.

Mobile and ephemeral data

Phones can contain texts, application messages, photographs, call records, location information and device artefacts. Some applications are designed to delete or expire content. The fact that information is transient does not automatically make it irrelevant; it makes timely identification and preservation more important.

Cloud and SaaS data

Cloud systems change continuously. Permissions, versions, links and retention settings may affect what can be found later. Collection may rely on platform exports, APIs or specialist tools rather than copying files from a local disk.

Why ESI creates discovery challenges

Volume is only one problem. Variety, duplication, access controls, encryption, changing content, privacy obligations, cross-border restrictions and proprietary formats can all affect the workflow. The central question is not “How much data exists?” but “Which information sources can answer the issues in this matter, and how should they be handled?”

A practical example

A sales dispute may involve an email agreeing a price, a CRM entry showing the opportunity stage, a Teams conversation discussing an exception and a spreadsheet containing the final forecast. None tells the whole story alone. ESI becomes evidence through context and relationship.

Practitioner implication

Data-source literacy is now a core eDiscovery skill. Professionals do not need to be engineers for every platform, but they do need to recognise when the structure of a source affects preservation, collection, search, review and interpretation.

Practitioner takeaways

  • Start with the purpose of the matter and the questions the evidence must answer.
  • Treat legal, technical and evidential decisions as connected rather than isolated tasks.
  • Use proportionate methods, validate important results and record material decisions.
  • Preserve context and metadata where they affect meaning, authenticity or later analysis.
  • Use technology and AI to support professional judgement, not to disguise weak process.

Related eDiscovery Certification Council Knowledge Hub reading

Authoritative reference points

This is a vendor-neutral professional reference from the eDiscovery Certification Council Knowledge Hub. Jurisdiction-specific legal requirements should be checked against the current applicable rules and authoritative guidance.