The First EDisclosure Meeting 50 Questions Lawyers Should Ask
23 pages · 29 min read
The First eDisclosure Meeting 50 Questions Lawyers Should Ask
The First eDisclosure Meeting 50 Questions Lawyers Should Ask
Guide · 23 pages · 29 min read · Published 2026-08-29
The First eDisclosure Meeting 50 Questions Lawyers Should Ask
Read this guide on your phone, browse guides by topic or go back to the full PDF library.
23 pages · 29 min read
The First eDisclosure Meeting 50 Questions Lawyers Should Ask
THEFIRSTMEETING · AGUIDEFORUKLAWYERS The First eDisclosure Meeting 50 Questions Lawyers Should Ask COMPUTERFORENSICSLAB § ABOUTTHEAUTHOR PRE PA REDBYCOMPUTERFORENSICSLABE - DISCOVERYTEAM FULL CHAIN-OF-CUSTODY DOCUMENTATION § CONTENTS In this guide 01 Executive summary 02 Why the first meeting matters, practically and legally 03 How to run the meeting 04 Questions 1–5 · IT architecture 05 Questions 6–10 · Custodians 06 Questions 11–15 · Devices 07 Questions 16–20 · Cloud services 08 Questions 21–25 · Deleted data 09 Questions 26–30 · Retention and backups 10 Questions 31–35 · Preservation actions 11 Questions 36–40 · Privacy and data protection 12 Questions 41–45 · Privilege 13 Questions 46–50 · Third parties 14 After the meeting: converting answers into actions 15 Red-flag answers 16 Common mistakes · Suggested wording 17 Checklist · When to involve a digital forensic expert 18 Frequently asked questions 19 Glossary · References · Disclaimer · How a specialist laboratory can assist § 0 1 · ORIENTATION Executive summary THEHEADLINEPOINT : WHYFIFTYSTRUCTUREDQUESTIONS § 0 2 · FIRSTPRINCIPLES Why the first meeting matters, practically and legally § 0 3 · METHOD How to run the meeting § 0 4 · QUESTIONS1 – IT architecture 1 · Walk me through where the organisation's data lives: email platform, file storage, chat and collaboration tools, business systems, and anything else with company information in it. 2 · Who administers those systems, and are any managed by an outside IT provider? Who holds global administrator rights? 3 · Is there a systems inventory, asset register or data map, however informal? Can we have it? 4 · What has changed in the estate over the relevant period: migrations, new platforms, decommissioned systems, mergers or rebrands with old domains? 5 · Which business systems record the transactions or events this dispute is about (CRM, ERP, finance, quality, sector systems), and who understands each one? § 0 5 · QUESTIONS6 – 1 Custodians 6 · Who was actually involved in the events behind this dispute: who negotiated, decided, approved, performed and recorded? Not the org chart; the people who did the work. mailbox or manage their diary? here, and on what timetable? project channel)? Who has access to each? § 0 6 · QUESTIONS11 – 1 Devices too? months before)? 15 · Do people use removable media (USB drives, external disks) or connect personal storage to work machines? § 0 7 · QUESTIONS16 – 2 Cloud services project tools, sector applications, anything paid by subscription? 17 · Do staff use personal cloud accounts (personal Gmail, Dropbox, iCloud) for anything work-related, officially or not? 18 · What messaging apps are used for business: WhatsApp, Signal, Telegram, iMessage? By whom, with whom, and are disappearing-message settings on anywhere? controls and export capability? 20 · Who are the cloud accounts actually registered to? Any business accounts on a founder's or employee's personal email, or a personal number running WhatsApp Business? § 0 8 · QUESTIONS21 – 2 Deleted data 21 · Has anyone deleted, cleaned up, exported or reorganised anything potentially relevant since this dispute arose, or in anticipation of it? This is a safety question, not an accusation. 22 · Has anyone already investigated internally: IT looking through a laptop, HR reviewing a mailbox, a manager checking a leaver's files? items folders, retention holds? you think so? involve here? § 0 9 · QUESTIONS26 – 3 Retention and backups 26 · What retention and auto-deletion policies are configured right now on email, chat and drives: the actual settings, not the policy document? (tapes, old systems) needing special handling? 30 · Have retention settings, hold policies or backup schedules been changed by anyone since the dispute arose? § 1 0 · QUESTIONS31 – 3 Preservation actions acknowledge on behalf of IT operations? 34 · Is anything volatile enough that it should be forensically preserved this week: suspect devices, key handsets, CCTV, a leaver's laptop? confirmation that preservation steps have been taken? § 1 1 · QUESTIONS36 – 4 Privacy and data protection 36 · What personal data will the exercise inevitably touch: employees' communications, customers' information, special-category data in HR or health contexts? 37 · What do staff-facing policies say about monitoring and the company's access to work communications, and what have staff actually been told? 38 · Where personal devices hold work material, are the individuals likely to cooperate with a targeted, privacy- protective extraction? Any relationships already strained? 39 · Is any relevant data outside the UK: foreign subsidiaries, overseas servers, custodians abroad? Any jurisdictions with strict local rules? 40 · Is there a live data-protection dimension already: a breach, an ICO interaction, subject access requests from the opponent or departing staff? § 1 2 · QUESTIONS41 – 4 Privilege 41 · Which lawyers have touched these matters: external firms, in-house counsel, and in-house lawyers wearing commercial hats? 42 · Was there an internal investigation, review or report into these events? Who commissioned it, who conducted it, and for what stated purpose? 43 · How does advice travel internally: is legal advice forwarded into business threads, summarised in board packs, pasted into chat? 44 · Is there any joint, shared or common-interest dimension: co-defendants, insurers, group companies sharing advice, prior transactions with shared counsel? adviser? § 1 3 · QUESTIONS46 – 5 Third parties 46 · Which outside organisations hold or process company data: the MSP, hosting and backup providers, payroll, accountants, records storage? Where did the data go at exit? the correspondence? 49 · Are there carriers, banks or platforms whose records may matter: call records, payment flows, platform accounts and their logs? 50 · Is any other proceeding, regulator or authority already touching this data: police, a regulator, an insurer's investigators, parallel litigation? § 1 4 · CONVERSION After the meeting: converting answers into actions ANSWER CLUSTER IMMEDIATE OUTPUT FEEDS INTO § 1 5 · ESCALATIONTRIGGERS Red-flag answers THE ANSWER THE SAME-DAY ACTION § 1 6 · WHEREITGOESWRONG & DRAFTINGAIDS Common mistakes · Suggested wording Common mistakes Suggested wording · Meeting request to the client (core paragraphs) Suggested wording · Post-meeting confirmation request (core paragraphs) § 1 7 · QUICKCONTROL Checklist · When to involve a digital forensic expert The first-meeting checklist When to involve a digital forensic expert § 1 8 · COMMONQUESTIONS Frequently asked questions Who should attend the first meeting? What if IT is fully outsourced? What if the client cannot answer many of the questions? How long does this take, and can it be split? Should we run this meeting pre-action? Is this meeting privileged, and does the note get disclosed? § 1 9 · REFERENCE Glossary MSP Sources and authoritative references DISCLAIMER § HOWASPECIALISTLABORATORYCANASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY
Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.