{"id":1240,"date":"2013-04-03T14:28:55","date_gmt":"2013-04-03T14:28:55","guid":{"rendered":"http:\/\/jolt.richmond.edu\/?p=1240"},"modified":"2019-03-08T19:52:36","modified_gmt":"2019-03-09T00:52:36","slug":"databases-lie-successfully-managing-structured-data-the-oft-overlooked-esi","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2013\/04\/03\/databases-lie-successfully-managing-structured-data-the-oft-overlooked-esi\/","title":{"rendered":"Databases Lie!  Successfully Managing Structured Data, the Oft-Overlooked ESI"},"content":{"rendered":"<p style=\"text-align: left\" align=\"center\"><a href=\"http:\/\/jolt.richmond.edu\/v19i3\/article9.pdf\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-128\" alt=\"pdf_icon\" src=\"http:\/\/jolt.richmond.edu\/files\/2012\/05\/pdf_icon1.gif\" width=\"16\" height=\"16\" \/>Download PDF<\/a><\/p>\n<p style=\"text-align: center\">Cite as: Conrad Jacoby, Jim Vint &amp; Michael Simon, <em>Databases Lie!\u00a0Successfully Managing Structured Data, The Oft-Overlooked ESI<\/em>, 19\u00a0RICH. J.L. &amp; TECH 9 (2013), available at\u00a0http:\/\/jolt.richmond.edu\/v19i3\/article9.pdf.<\/p>\n<p>&nbsp;<\/p>\n<p align=\"center\">By Conrad Jacoby,* Jim Vint,** &amp; Michael Simon***<\/p>\n<p>&nbsp;<\/p>\n<p>[1]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Legal professionals regularly advise clients to ensure that the storage, retention, and accessibility of their Electronically-Stored Information (\u201cESI\u201d) is in full compliance with all legal and regulatory requirements in the event this information becomes relevant in civil, criminal, or regulatory disputes.\u00a0 However, what many practitioners may not realize is that the ESI that clients are required to produce for e-discovery includes both \u201cunstructured\u201d and \u201cstructured\u201d data.\u00a0 Searching and producing only one of these types of ESI may well not fully satisfy a client\u2019s full discovery obligations.\u00a0 Even worse, it might not present a full understanding of the factual issues in the matter and how to best prove them to the legal team.<\/p>\n<p>&nbsp;<\/p>\n<h3 align=\"center\"><b>I.\u00a0 What Is \u201cStructured Data?\u201d<\/b><\/h3>\n<p>[2]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Most legal professionals are extremely familiar with \u201cunstructured\u201d or \u201cloose\u201d data, even if they do not necessarily know it by these terms.\u00a0 Simply put, unstructured data refers to e-mail messages, word processing documents, spreadsheets, and presentations, among other things\u2014in other words, human-readable information that is commonly sought as potentially relevant ESI in discovery.[1]\u00a0 Structured data, on the other hand, refers to information residing in electronic repositories or silos, such as transactional and financial databases.[2]\u00a0 Unlike unstructured data, which typically exists as static and self-contained files that are preserved, collected, processed, reviewed, authenticated, and admitted into evidence as stand alone documents, structured data exists as segments of information inside a larger system, one that is often quite complex and contains many parts.[3]\u00a0 A database record, the closest analog that structured data has to a \u201cdocument,\u201d may not actually exist until a user performs some action through the database system to assemble a number of separate fields that could reside in many different parts of the system.\u00a0 For this reason, information stored in a database cannot be placed into a standard e-discovery review system that has been optimized to view and categorize unstructured data.<\/p>\n<p>[3]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The ESI stored in databases and other structured data repositories is every bit as relevant and discoverable as the loose files that are more commonly requested.\u00a0 Federal Rule of Civil Procedure (\u201cFRCP\u201d) 34 is clear and unambiguous on this point:<\/p>\n<p style=\"padding-left: 30px\"><em>Rule 34.\u00a0 Producing Documents, Electronically Stored Information, and Tangible Things, or Entering onto Land, for Inspection and Other Purposes<\/em><\/p>\n<p style=\"padding-left: 30px\"><em>(a) In General.\u00a0 A party may serve on any other party a request within the scope of Rule 26(b):<\/em><\/p>\n<p style=\"padding-left: 60px\"><em>(1) to produce and permit the requesting party or its representative to inspect, copy, test, or sample the following items in the responding party&#8217;s possession, custody, or control:<\/em><\/p>\n<p style=\"padding-left: 90px\"><em>(A) any designated documents or electronically stored information\u2014including writings, drawings, graphs, charts, photographs, sound recordings, images, and other <b>data or data compilations<\/b>\u2014stored in any medium from which information can be obtained either directly or, if necessary, after translation by the responding party into a reasonably usable form[.][4]<\/em><\/p>\n<p>[4]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Unlike the discovery of unstructured data, for which a number of best practices have emerged, it has been difficult for the legal industry to develop best practices for the treatment of structured data in civil discovery due to the vast diversity of size, scope, and features found in different database systems.\u00a0 The Sedona Conference<sup>\u00ae<\/sup>, a non-partisan legal think-tank founded in 1997, formed a group in early 2009 to study the issues surrounding the discovery of structured data\u2014culminating in the publication of <i>The Sedona Conference<\/i><i><sup>\u00ae<\/sup><\/i><i> Database Principles Addressing the Preservation and Production of Databases and Database Information in Civil Litigation<\/i> (hereinafter the \u201c<i>Sedona Database Principles<\/i>\u201d) in April 2011.[5]\u00a0 The <i>Sedona Database Principles<\/i> expand upon the original publication, <i>The Sedona Principles: Best Practices Recommendations &amp; Principles for Addressing Electronic Document Production<\/i> (hereinafter the \u201c<i>Sedona Principles<\/i>\u201d),[6] as they specifically apply to databases and set out six additional precepts that provide practical suggestions for simplifying the discovery of structured data and clarifying the obligations of both the requesting and producing parties.[7]\u00a0 An overarching theme of the <i>Sedona Database Principles<\/i> is that better communication between parties, their legal advisors and agents, and information technology professionals will substantially improve the management of this type of specialized ESI in legal disputes.[8]\u00a0 To that end, the <i>Sedona Database Principles<\/i> specifically reference many of the precepts of the <i>Sedona Principles<\/i> that address and encourage cooperation between the parties.[9]<i><\/i><\/p>\n<p><b>\u00a0<\/b><\/p>\n<h3 align=\"center\"><b>II. \u00a0How Does Structured Data Become Relevant?<\/b><\/h3>\n<p>[5]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Databases frequently record historical transactions and information that is relevant in litigation and investigations.\u00a0 One would certainly expect that enterprise-level systems like Oracle and SAP, not to mention financial and transactional systems, human resource tracking systems, data warehouses, and content management systems (\u201cCRM\u201d), would all contain structured data.\u00a0 However, other commonly used systems, including Cloud-based \u201cSoftware-As-A-Service\u201d (\u201cSaaS\u201d) systems, also feature the same back-end structured data systems as more obvious \u201cdatabase\u201d systems.\u00a0 Thus, structured data has largely replaced loose documents for tracking information for these and other similar functions: accident\/incident reporting systems, call center records and associated data analytics, world wide web servers, point of sale systems, and social media.<\/p>\n<p>[6]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The cumulative volume of data in business-related structured data repositories is immense and is projected to grow at an estimated annual rate of nearly twenty percent.[10]\u00a0 Perhaps even more important to e-discovery practitioners, a recent survey about the state of discovery in civil litigation has shown that e-mail, the central focus of e-discovery requests for over fifteen years, is no longer the leading requested item.[11]\u00a0 Instead, database and application data are now more often requested.[12]<\/p>\n<p>[7]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 An increasing number of litigation disputes involving \u201chigh profile\u201d companies have made demands upon litigants to review, disclose, and produce at least portions of their databases.\u00a0 Several examples are explored below.<\/p>\n<p>[8]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The plaintiffs in <i>In re eBay Seller Antitrust Litigation<\/i>, an antitrust class action, sought production of transactional data from defendant eBay<i>.<\/i>[13]<i>\u00a0 <\/i>The court granted the motion in part and eBay objected, claiming that the information sought did not already exist in easily compiled form, requiring eBay \u201cto spend hundreds of thousands of dollars to dedicate a highly specialized engineering resource for a period of more than six months to create new data<br \/>\n\u201d solely for the matter.[14]\u00a0 However, eBay\u2019s own submissions in support of the objection contained three different estimates, ranging from a low of $179,000 to a high of $300,000.[15]\u00a0 Moreover, eBay\u2019s employee in charge of data warehouse development declared that the provided estimate could vary \u201cby as much as five hundred percent.\u201d[16]\u00a0 The court first disposed of eBay\u2019s argument that it could not be required to create anything new, finding that FRCP 34(a)(1)(A) supported the magistrate\u2019s finding that the technical burden of creating the new material did not excuse production.[17]\u00a0 In light of the hundreds of millions of dollars at stake in the action involving a defendant with billions of dollars in annual gross profits, and considering that the magistrate had already scaled back the scope of discovery, the court found no clear error in the magistrate\u2019s determination that the potential costs and technical requirements were not unduly burdensome.[18]<\/p>\n<p>[9]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 In another case, a plaintiff injured by a sink that fell from a high storeroom shelf sought production of the database that the defendant, Lowe\u2019s, used to record and track accident and injury claims.[19]\u00a0 The trial court ordered Lowe\u2019s to present a witness with knowledge and access to the system and to print out all requests for accidents occurring before the date of the plaintiff\u2019s injury.[20]\u00a0 Notably, Lowe\u2019s objected that: (1) it had already produced a printout from the database of all falling merchandise claims for its stores within the state for the last five years; (2) the remaining portions of the database were not relevant; (3) the manner in which accident information was gathered and stored was a trade secret; (4) the purpose of the database was not for safety-related information; and (5) there was no way to restrict production of privileged or non-relevant information.[21]\u00a0 The appellate court agreed with Lowe\u2019s in part and limited the plaintiffs from accessing data without limitation as to time, place, or subject matter.[22]<\/p>\n<p>[10]\u00a0\u00a0\u00a0\u00a0\u00a0 In <i>Procter &amp; Gamble v. Haugen<\/i> a plaintiff appealed from the dismissal of his Lanham Act and tortious interference claims which resulted in part from the court sanctioning it for failing to preserve relevant database information.[23]\u00a0 Procter &amp; Gamble (\u201cP&amp;G\u201d) claimed that agents of a competitor spread false rumors that the company supported Satanism, using the profits from forty-three products to do so.[24]\u00a0 P&amp;G and its expert witnesses used the services of a third party vendor, Information Resources Incorporated (\u201cIRI\u201d), to track potential lost sales of the forty-three involved products.[25]\u00a0 IRI used a database that gathered purchase information from retail stores into electronic market share databases.[26]\u00a0 IRI\u2019s databases stored data on a \u201crolling\u201d basis so that data was kept only for a period of time before it was deleted from the system to make room for more data.[27]\u00a0 Defendants requested production of all of the information that P&amp;G used from the IRI databases and when P&amp;G was unable to produce all of this information, the court found that P&amp;G had spoliated the data and dismissed the matter as a sanction.[28]\u00a0 On appeal, P&amp;G focused on the fact that it was only a subscriber to the IRI database, did not own or control the system, and therefore could not have practicably provided the information to defendants.[29]\u00a0 P&amp;G could have provided direct access to the system to defendants, but this would not have covered all of the information they sought.[30]\u00a0 P&amp;G would have had to pay over thirty million dollars to obtain all of the information from IRI and even if it had, it would not have had sufficient storage capacity for the data.[31]\u00a0 The court of appeals found that the district court had failed to address the fact that P&amp;G did not \u201cpossess\u201d the data and along with the defendants\u2019 failure to prove prejudice, reversed the sanctions order.[32]<\/p>\n<p>[11]\u00a0\u00a0\u00a0\u00a0\u00a0 In another case involving a Lanham Act claim, a plaintiff sought discovery about the defendants\u2019 sales of an alleged infringing product. [33]\u00a0 One of those defendants, Wal-Mart, responded with 1,771 pages of Bates-stamped documents that represented a print-out of the tabular view of the raw data within its sales database.[34]\u00a0 Plaintiff claimed that the printouts, with line item data arranged by columns and UPC codes, was \u201cindecipherable\u201d and thereby an insufficient response.[35]\u00a0 The court was \u201cconvinced\u201d that Wal-Mart\u2019s burden in deriving the information from the database was \u201csignificantly less\u201d than on the plaintiff since Wal-Mart controlled the system.[36]\u00a0 For this reason, the court granted plaintiff\u2019s motion to compel a more sufficient response from Wal-Mart.[37]<\/p>\n<p>[12]\u00a0\u00a0\u00a0\u00a0\u00a0 Finally, in an Americans with Disabilities Act claim, the Equal Employment Opportunity Commission (\u201cEEOC\u201d) sought to compel production of portions of the human resources database of a Supervalu and Jewel-Osco, major national food retailers.[38]\u00a0 The EEOC originally sought broad production of information from the human resources database, but narrowed its requests after a meet and confer session to employee hiring, transfer, and termination records, along with job postings for the subject time period.[39]\u00a0 The EEOC premised its request on the defendants\u2019 own FRCP 30(b)(6) testimony that \u201cthis sort of analysis could be completed\u201d and that defendants\u2019 \u201ctypes of database are designed for this sort of production at minimal expense.\u201d[40]\u00a0 Defendants first claimed that they did not have the particular database tool activated in their system to allow them to provide the information requested by the EEOC.[41]\u00a0 Defendants then objected to the scope and burden of the request, claiming that the information would cover over 180 locations and 100,000 employees (when there were only 108 claimants) and that it would take their IT personnel over a week to write the code necessary to obtain the data.[42]\u00a0 The court found that the EEOC had not established that the relevance or benefit of the information outweighed the burden and expense of producing it and thus denied the motion to compel.[43]<\/p>\n<p>&nbsp;<\/p>\n<h3 align=\"center\"><b>III.\u00a0 Can a Party Wait to Deal with Structured Data until that Information Has Been Requested?<\/b><\/h3>\n<p>[13]\u00a0\u00a0\u00a0\u00a0\u00a0 The information contained in databases can make the difference between winning and losing a case.\u00a0 The <i>Sedona Database Principles<\/i> makes this statement as a matter of<br \/> plain fact: \u201cInformation contained in databases may be the best source for establishing certain facts in a legal dispute.\u00a0 Information stored in this format also may be useful, if not essential, for analyses such as sorting, calculating, and linking to answer quantitative questions presented in a case.\u201d[44]<\/p>\n<p>[14]\u00a0\u00a0\u00a0\u00a0\u00a0 It is a simple matter to move from the abstract language of the <i>Sedona Database Principles<\/i> to concrete situations.\u00a0 Unstructured data, particularly e-mail, instant messages (\u201cIM\u201d), and typical \u201coffice\u201d documents (<i>i.e<\/i>., Microsoft Word, Excel, and PowerPoint) provides evidence of the communication of activities\u2014who knew what and when.\u00a0 People will write e-mail and text messages to others concerning what they did.\u00a0 Similarly, they will draft documents to memorialize actions that they have taken.\u00a0 In contrast, the structured data in transactional and financial databases provides direct evidence of the action\u2014how, how much, and how often.\u00a0 The financial system will show that money was moved and the time and accounts involved.\u00a0 A transactional application will record the supervisor\u2019s approval of the money transfer.\u00a0 Thus, the database systems provide a way to \u201cfollow the money\u201d and recreate what happened, even if the communications record is incomplete or, in the case of fraud or shady dealing, deliberately obscured.\u00a0 For this reason, some have called structured data \u201cforgotten data\u201d\u2014\u201cperhaps the single biggest missed opportunity for de<br \/>\nfense in e-discovery.\u201d[45]<\/p>\n<p>&nbsp;<\/p>\n<h3 align=\"center\"><b>IV.\u00a0 Planning for Discovery of Structured Data<\/b><\/h3>\n<p>[15]\u00a0\u00a0\u00a0\u00a0\u00a0 Databases, especially major, enterprise, or department-level systems, are often highly complex and highly customized.\u00a0 The discovery of structured data typically requires specific expertise with experience in deciphering data structures, relationships, and connections to other systems.\u00a0 The <i>Sedona Database Principles<\/i> is filled with warnings about the need for expert assistance,[46] and it likens the act of trying to handle discovery requests involving structured data without such knowledge as \u201cakin to seeing a thousand-piece jigsaw puzzle without an illustration that shows the final completed puzzle.\u201d[47]<\/p>\n<p>[16]\u00a0\u00a0\u00a0\u00a0\u00a0 Seeking information stored in structured data repositories also requires more planning\u2014and often more efforts at cooperation between the parties\u2014than traditional e-discovery.\u00a0 Parties that do not meet and confer before commencing structured data requests may well find that the court sends them back to square one.[48]\u00a0 Many reasons exist for this heightened need for additional proactive planning and discussion, but none may be more pressing than the fact that downstream production requirements will control the early stage EDRM work conducted in Preservation, Collection, and Processing, and even potentially as far back as the critical Identification phase of e-discovery.<\/p>\n<p>[17]\u00a0\u00a0\u00a0\u00a0\u00a0 It should come as no surprise that the <i>Sedona Database Principles<\/i> places particular emphasis on one of the core principles from the original <i>Sedona Principles<\/i>:<\/p>\n<p style=\"padding-left: 30px\"><em>Sedona Principle 3: The Early \u201cMeet and Confer\u201d<\/em><\/p>\n<p style=\"padding-left: 30px\"><em>\u201cParties should confer early in discovery regarding the preservation and production of electronically stored information when these matters are at issue in the litigation and seek to agree on the scope of each party\u2019s rights and responsibilities.\u201d<\/em><\/p>\n<p>Sedona Principle 3 is especially applicable in the context of database discovery because of the complicated technical and logistical questions raised by the storage of information in databases.\u00a0 Database discovery may entail some of the most expensive and complex discovery in a litigation matter, and meaningful conversations between the parties early in the litigation can substantially reduce confusion and waste of resources.[49]<\/p>\n<p>[18]\u00a0\u00a0\u00a0\u00a0\u00a0 Challenges to the discovery of information stored in structured data repositories can occur from both opposing parties and litigants.\u00a0 Many of the solutions for best using data from databases require the creation of a new view or analysis that differs from the way that the information is used in the ordinary course of business.\u00a0 Responding to structured data requests is likely to require new reports, new extracts directly from the systems, or even entirely new systems to analyze data.\u00a0 Attorneys are often not comfortable with this process, especially since information about how these new views of structured data were created may have to be disclosed to the other side if challenges arise as to the adequacy of the proffered discovery response.\u00a0 Thus, it is critical to complete a full and frank discussion, between <i>all<\/i> stakeholders\u2014each side and each role (Legal, IT, outside expert)\u2014that clearly sets out all expectations before any work begins.<\/p>\n<p>[19]\u00a0\u00a0\u00a0\u00a0\u00a0 The first issue that practitioners are likely to confront during the e-discovery process involves the specific elements that will be extracted from the database.\u00a0 In some situations, it may be necessary to preserve and collect elements that would not normally be considered \u201ccontent,\u201d such as reports, formulas, pick lists, reports, queries, and the like.[50]\u00a0 For example, FLSA class action litigation often revolves around issues of how companies determined which employees were exempt from overtime and which were non-exempt; formulas within the HR and payroll systems applying these standards become critical.[51]\u00a0 Fraud cases that center around who knew what and when could require the recreation of standard reports and views that were used at the time of the alleged suspicious activity.[52]\u00a0 Such elements will almost certainly require rigorous preservation and collection methods, such as a complete database copy or a restored full back up, as outlined below.<\/p>\n<p>[20]\u00a0\u00a0\u00a0\u00a0\u00a0 In most cases, practitioners will need to focus solely on database content: the fields and records.\u00a0 With this approach, legal teams must anticipate potential issues as they either use or produce this information.\u00a0 Concerns include: (1) a need for completeness and usability of the data set; (2) availability of the data and technical feasibility of any planned search and retrieval Methods; and (3) cost.\u00a0 Each concern is explored in turn below.<\/p>\n<h3 style=\"padding-left: 30px\"><b>A.\u00a0 A Need for Completeness and Usability of the Data Set<\/b><\/h3>\n<p>[21]\u00a0\u00a0\u00a0\u00a0\u00a0 The fact that some of the data within a database may be relevant does not mean that the entire database must be produced.\u00a0 Sedona Database Principle 1: Scope of Discovery clearly speaks to this point: \u201cAbsent a specific showing of need or relevance, a requesting party is entitled only to database fields that contain relevant information, not the entire database in which the information resides or the underlying database application or database engine.\u201d[53]<\/p>\n<p>[22]\u00a0\u00a0\u00a0\u00a0\u00a0 Will legal teams require a complete set of data or merely an extensive subset of potentially relevant records?\u00a0 For a small subset of data, a surgical approach will likely suffice.\u00a0 However, if a complete dataset will be required for further analysis, the scope of database preservation, collection, and production will be much more extensive.\u00a0 Date ranges for activity or database information creation may be helpful at this stage.<\/p>\n<p>[23]\u00a0\u00a0\u00a0\u00a0\u00a0 Does the team require a picture of the information present at a particular point in time?\u00a0 If so, a snapshot of the data or the system will likely accomplish these objectives.\u00a0 To create a historical record, a trend line, or to illustrate changes over time, more comprehensive preservation and collection will be required.<\/p>\n<h3 style=\"padding-left: 30px\"><b>B.\u00a0 Availability of the Data and Technical Feasibility of any Planned Search and Retrieval Methods<\/b><\/h3>\n<p>[24]\u00a0\u00a0\u00a0\u00a0\u00a0 Structured data systems have a variety of capabilities and technical capacity.\u00a0 Many of the older legacy systems can be very limited in how one can manipulate and export data.\u00a0 Thus, before making any plans\u2014or worse, commit to a regulator or the other side in litigation as to a methodology or deliverable data\u2014it is critical to determine whether the target system includes the necessary capabilities.\u00a0 The answer to this question will vary by the circumstances of each case, but some of the questions highlighted in Comment 2B of the <i>Sedona Database Principles<\/i>[54] provide a good starting point:<\/p>\n<p style=\"padding-left: 30px\"><em>Can a user run searches within the system, other than those built specifically for the intended business uses of the database?[55]<br \/> <\/em><br \/> <em>Will the searches bring back complete information (i.e., all the requested data)?[56]<br \/> <\/em><br \/> <em>Is there information stored outside of \u00a0fielded tables?[57]<br \/> <\/em><br \/> <em>Does the producing party have custody and control of the database, such that it can access the \u201cback end\u201d of the system to export data, create custom reports, or otherwise access the system outside of normal business use?[58]<br \/> <\/em><br \/> <em>Does the system support third party tools that might be more efficient at querying the data?[59]<br \/> <\/em><br \/> <em>Does the system have reporting capabilities?[60]<br \/> <\/em><br \/> <em>Does the system support the creation of custom reports?<\/em><\/p>\n<p>[25]\u00a0\u00a0\u00a0\u00a0\u00a0 The answers to these and other questions will directly impact the extent to which a case team can preserve, collect, and ultimately produce the data stored w<br \/>\nithin a database system.\u00a0 It is crucial that qualified personnel correctly provide this essential foundational information.\u00a0 It may be necessary to support such statements with documented expert evidence.\u00a0 Given a lesser evidentiary showing, the courts have shown little sympathy for such claims, particularly when made by sophisticated corporations.[61]<\/p>\n<h3 style=\"padding-left: 30px\"><b>C.\u00a0 Cost<\/b><\/h3>\n<p>[26]\u00a0\u00a0\u00a0\u00a0\u00a0 Structured data discovery has the potential to be more costly than \u201cstandard\u201d requests.\u00a0 It is imperative that parties have a strong understanding of the potential costs associated with structured data discovery.\u00a0 Courts have become particularly sensitive over recent years to knee-jerk undue burden and cost claims under FRCP 26(b)(2)(B) that lack concrete documented support.[62]\u00a0 This concern is yet one more reason why retaining experienced experts, who can attest to costs encountered in similar situations, may be critical to adequately educate both courts and requesting parties.<\/p>\n<p>&nbsp;<\/p>\n<h3 align=\"center\"><b>V.\u00a0 Handling Structured Data within the EDRM<\/b><\/h3>\n<p>[27]\u00a0\u00a0\u00a0\u00a0\u00a0 The Electronic Discovery Reference Model (\u201cEDRM\u201d) has come to provide an industry-accepted workflow for e-discovery across the litigation lifecycle.\u00a0 Discovery of structured data can generally proceed within the EDRM framework, though a number of modifications may be required because of the unique requirements inherent in handling this type of ESI.\u00a0 Virtually all structured data projects will require the application of an IT concept known as \u201cETL,\u201d which is the acronym for Extract, Transform, and Load.\u00a0 A good working definition for ETL is:<\/p>\n<p style=\"padding-left: 30px\"><em>ETL is short for extract, transform, load, three database functions that are combined into one tool to pull data out of one database and place it into another database.\u00a0 [Extract] is the process of reading data from a database.\u00a0 [Transform] is the process of converting the extracted data from its previous form into the form it needs to be in so that it can be placed into another database.\u00a0 Transformation occurs by using rules or lookup tables or by combining the data with other data.\u00a0 [Load] is the process of writing the data into the target database.[63]<\/em><\/p>\n<p>[28]\u00a0\u00a0\u00a0\u00a0\u00a0 ETL is required in e-discovery for the simple reason that most business-oriented database systems (<i>e.g<\/i>., Peoplesoft, Cognos, Oracle Financials, specialized procurement software, and SQL databases) are designed to meet specific business needs and do not inherently \u201cspeak\u201d to each other.\u00a0 Hence, ETL permits different data formats to be assimilated or aggregated in a unified source for analysis.\u00a0 This saves time querying multiple databases in various coding languages to try to quantify an impact, establishing relationships with the data across systems, and providing meaningful results to counsel and client.<\/p>\n<p>[29]\u00a0\u00a0\u00a0\u00a0\u00a0 For structured data, a typical workflow involves an ETL overlay of several EDRM phases, beginning with Identification and typically running through Preservation and Collection, and at times into the Processing phase.\u00a0 This process is illustrated in the figure reproduced in the Appendix.<\/p>\n<h3 style=\"padding-left: 30px\"><b>A.\u00a0 Identification<\/b><\/h3>\n<p>[30]\u00a0\u00a0\u00a0\u00a0\u00a0 The Identification phase for structured data is likely to require substantially more experience than it normally would for unstructured data systems.\u00a0 Large-scale enterprise database systems, such as Oracle, SAP and PeopleSoft, are highly complicated and customized, requiring advisors with specialized expertise to understand them.\u00a0 This complexity may even be considered a trade secret and thus protected by the software vendor.[64]\u00a0 Even small-scale systems as simple as Microsoft Access databases are often customized and connected to other systems in ways that are both unexpected and poorly documented.\u00a0 Older structured data repositories that fall into the categories of legacy data, obsolete hardware, and retired systems may present particular concerns since the documentation that existed at one time may no longer be available or accurate.\u00a0 Further, the employees who created and maintained these systems may be long gone from the company, having taken with them any institutional knowledge about these systems.<\/p>\n<p>[31]\u00a0\u00a0\u00a0\u00a0\u00a0 For all of the above reasons, Sedona Principle 6: Responsibilities of Responding Parties is particularly applicable to and significant for the discovery of structured data.\u00a0 Sedona Principle 6 reads: \u201cResponding parties are best situated to evaluate the procedures, methodologies, and technologies appropriate for preserving and producing their own electronically stored information.\u201d[65]\u00a0 The <i>Sedona Database Principles<\/i> further apply this guidance to the discovery of structured data in Database Principle 2: Accessibility and Proportionality, which states: \u201cDue to the differences in the way that information is stored or programmed into a database, not all information in a database may be equally accessible, and a party\u2019s request for such information must be analyzed for relevance and proportionality.\u201d[66]<\/p>\n<p>[32]\u00a0\u00a0\u00a0\u00a0\u00a0 However, the fact that a producing party is generally better situated to evaluate methodologies and burdens does not mean that the responding party can and should examine and evaluate such information unilaterally.\u00a0 In accord with the <i>Sedona Database Principles<\/i>\u2019 focus on cooperation between the parties, Database Principle 3: Use of Test Queries and Pilot Projects recommends that the parties work together, starting with the sharing of database and system documentation or even going so far as to create test queries and pilot projects.\u00a0 It states: \u201cRequesting and responding parties should use empirical information, such as that generated from test queries and pilot projects, to ascertain the burden to produce information stored in databases and to reach consensus on the scope of discovery.\u201d[67]<\/p>\n<p>[33]\u00a0\u00a0\u00a0\u00a0\u00a0 Key goals in the identification phase should include:<\/p>\n<p style=\"padding-left: 30px\"><em>Determining which systems are likely to include data that might need to be used or produced;<br \/> <\/em><br \/> <em>Establishing the current status and availability of the data, such as whether it is still within live data systems, in legacy systems, in archives, on backup media, offline, legacy or retired systems;[68]<br \/> <\/em><br \/> <em>Locating the data, as many database systems have parts spread out among many physical locations, often in remote server farms or co-location facilities;[69]<br \/> <\/em><br \/> <em>Ascertaining who controls those systems (a vendor, such as SalesForce or other third party, rather than the client\/litigant, may actually have possession and day-to-day control over the database itself);<br \/> <\/em><br \/> <em>Understanding the functional purpose of those systems, both for which they were created and potentially for any later purpose or purposes for which they may be currently used;[70]<br \/> <\/em><br \/> <em>Determining the capabilities and limitations of the current system or media holding the data\u2014an important step that will set practical boundaries for how data can be preserved, collected and processed;<br \/> <\/em><br \/> <em>Assessing the costs and burdens of obtaining\u2014and if necessary restoring\u2014the data from its current storage repository; and<br \/> <\/em><br \/> <em>Evaluating the potential benefit of obtaining the data.<\/em><\/p>\n<p>[34]\u00a0\u00a0\u00a0\u00a0\u00a0 Data flow and entity relationship diagrams can be particularly useful in tracking down database connections, assuming the company has taken the time to create such documentation.\u00a0 This documentation augments the more technical documentation involved with <i>data mapping<\/i> and a <i>data dictionary <\/i>or <i>schema<\/i>.\u00a0 Data mapping, which is a list of how enterprise systems interconnect (sometimes prepared as a list, but sometimes created as an actual graphical map),[71] can make the difference between the success and failure of the project.\u00a0 Structured data systems connect to other systems within<br \/>\nthe enterprise, often to many systems and in surprising ways.\u00a0 Missing those connections can mean missing necessary inputs, outputs, and related or relevant data.<\/p>\n<p>[35]\u00a0\u00a0\u00a0\u00a0\u00a0 A data dictionary or schema shows the type of data that is in a system, how it is organized and named, and the relationships between that data as it sits in fields and tables.[72]\u00a0 Since structured data systems are often complicated and expensive, these tools tend to have long lives and may have changed purpose or focus over time.\u00a0 As it can be burdensome to modify an underlying data table structure, newer data may be stored in repurposed fields or tables that may not be properly named or intended for the current use.\u00a0 Such informal modifications are rarely fully documented unless a conscious (and recent) effort has been made to build a schema.\u00a0 However, as underscored by Comment 1B of the <i>Sedona Database Principles<\/i>, data that could initially appear to be irrelevant may in fact be relevant because of its relationship and connection to other data fields.[73]\u00a0 Thus, it is no surprise that the <i>Sedona Database Principles<\/i> propose that the responding party has a duty to provide the requestor with the information needed to convey a \u201cbasic understanding\u201d of the database system.[74]<\/p>\n<p>[36]\u00a0\u00a0\u00a0\u00a0\u00a0 A final challenge in the identification phase is that the most common users of these structured data systems, the end-users or \u201ccustomers\u201d who query the substantive information stored in the database, are unlikely to be experienced IT professionals.\u00a0 These users rarely have the time, knowledge, or ability to wade through technically confusing scenarios that a legal case team may pose.\u00a0 A case team must take this into account and plan to interview a mix of end-users and database-knowledgeable IT professionals in order to build a reasonable understanding of a complex structured data repository in active use.<\/p>\n<h3 style=\"padding-left: 30px\"><b>B.\u00a0 Preservation and Collection<\/b><\/h3>\n<p>[37]\u00a0\u00a0\u00a0\u00a0\u00a0 One of the most troubling aspects of e-discovery is that ESI has a tendency to disappear unless properly preserved.\u00a0 Backup tapes get recycled, e-mail servers are purged of ex-employee accounts, and hard drives from the laptops of ex-employees are reformatted and reused.\u00a0 Depending on the specific system at issue, some structured data repositories may be even worse in this regard.\u00a0 While much unstructured data is lost due to human action, certain types of common structured data systems are specifically designed to eliminate or overwrite data regularly and automatically, without anyone\u2019s direction or oversight.<\/p>\n<p>[38]\u00a0\u00a0\u00a0\u00a0\u00a0 These repositories stand in contrast to databases comprised of historical information, such as customer relationship management systems, complaint or incident databases, and financial systems used to determine trends, which are typically designed to log all inputted information.\u00a0 In these systems, where one of their intended uses is long-term \u201cdata mining\u201d for analytical purposes, the danger that information will disappear is appreciably less.<\/p>\n<p>[39]\u00a0\u00a0\u00a0\u00a0\u00a0 High volume transactional systems tend to overwrite data or regularly purge old data as the need for historical data is often limited and the volume of data that would build up over time would become prohibitively expensive to store.[75]\u00a0 This problem is well known and the drafters of the 2006 FRCP Amendments who added the rules on ESI specifically noted that \u201cmany database programs automatically create, discard, or update information\u201d and \u201cthat suspending or interrupting these features can be prohibitively expensive and burdensome.\u201d[76]\u00a0 Thus, practitioners assisting in a matter that touches these types of data systems will need to act quickly to preserve this type of system to avoid being left with incomplete data or none at all.[77]<\/p>\n<p>[40]\u00a0\u00a0\u00a0\u00a0\u00a0 Another unique wrinkle to the discovery of structured data is that the lines between the Preservation and Collection phases tend to blur.\u00a0 For structured data, the information that is preserved is often exactly what is collected.\u00a0 Most unstructured formats include potentially responsive files that are moved from at-risk locations (laptop hard drives, USB flash drives, unsecured network file stores, e-mail inboxes, <i>etc<\/i>.) to secure, locked down media or formats, pending further analysis.\u00a0 In contrast, non-purging structured data typically needs to be collected from the underlying system to be preserved.\u00a0 Thus, an already deadline-intensive e-discovery process can become more fraught with difficult-to-make and far-ranging early decisions.<\/p>\n<p>[41]\u00a0\u00a0\u00a0\u00a0\u00a0 It is important, however, to reemphasize that the fact that a database contains relevant information does not mean that the entire system must be locked down under a legal hold.\u00a0 Sedona Conference Principle 5: Duty of Preservation places a practical limit on the expectations of the parties: \u201cThe obligation to preserve electronically stored information requires reasonable and good faith efforts to retain information that may be relevant to pending or threatened litigation.\u00a0 However, it is unreasonable to expect parties to take every conceivable step to preserve all potentially relevant electronically stored information.\u201d[78]\u00a0 Thus, parties can use a number of different methods to collect and preserve structured data; the choice will be driven not by the impossible expectation of perfection, but by the circumstances of the case and the project scope questions previously discussed in \u201cPlanning for Discovery of Structured Data.\u201d[79]\u00a0 Each of these collection methodologies has advantages and disadvantages.\u00a0 Improperly applied, some methodologies have the potential to harm the information integrity of the underlying database and therefore, need to be used carefully or may need to be discussed more fully with the requesting party before moving forward.<\/p>\n<h4 style=\"padding-left: 60px\"><b>1.\u00a0 Forensic Collection of the Live Database<\/b><\/h4>\n<p>[42]\u00a0\u00a0\u00a0\u00a0\u00a0 Some disputes may require preservation and production of a complete copy of the database system.\u00a0 For example, this may be necessary where questions exist about the integrity or functionality of the database as a whole or if there is a need to manipulate the data in some way other than just as a historical record.<\/p>\n<p>[43]\u00a0\u00a0\u00a0\u00a0\u00a0 Collecting an entire database has some advantages, such as in situations where the complete dataset or evidence must be preserved.\u00a0 This method presents the path of least resistance to key issues of data verification and authentication in that data can be verified through MD5 or SHA-1 hash codes to authenticate it as the basis for its admissibility as factual evidence.\u00a0 Complete collection also presents the safest route against spoliation as any changes to a database in active service will not impact the version that was collected and is now out of tinkering hands.<\/p>\n<p>[44]\u00a0\u00a0\u00a0\u00a0\u00a0 That said, copying an entire structured data repository also has disadvantages when compared to other information collection methodologies.\u00a0 The first disadvantage is cost.\u00a0 Unless the system is small (<i>e.g<\/i>., desktop computer-based), the sheer size of a data repository may require large amounts of storage media, significant IT investment, and costly disruption to corporate operations.\u00a0 In addition, accessing a collected data repository may require building a comparable hardware and software environment to load, search, and otherwise manipulate the data.\u00a0 Enterprise-level infrastructure for this task is likely to be quite costly, even on a short-term leased basis.\u00a0 For older legacy systems, it might not even be possible to copy the system and even if were possible, duplicating the computer systems on which the information resides might have long become unavailable.\u00a0 Contractual rights may prevent this collection methodology.\u00a0 In the case of databases accessed over \u201cthe Cloud,\u201d copying the database as a whole is strictly forbidden both by license and deliberately-created technical constraints.[80]<\/p>\n<p>[45]\u00a0\u00a0\u00a0\u00a0\u00a0 It is im<br \/>\nportant to note that the preservation and collection of an entire database is rarely required for most legal disputes.\u00a0 Most e-discovery requests involve only a subset of structured data.\u00a0 Thus, collecting an entire database to preserve only a small amount of information within it incurs additional time and expense to search, cull, and select data, all of which will have to be done outside of the easy confines of an e-discovery review tool.<\/p>\n<h4 style=\"padding-left: 60px\"><b>2.\u00a0 Restoration of Backups from the Database<\/b><\/h4>\n<p>[46]\u00a0\u00a0\u00a0\u00a0\u00a0 Similar in outcome, but potentially less burdensome, disaster recovery backups of a structured data repository may be used to preserve and collect databases.\u00a0 Most organizations have regular business continuity backups of their key systems and it may be less onerous to divert one of these data snapshots than it would be to make a full copy of the live database.\u00a0 However, the same disadvantages apply as making a copy of the system, along with some additional challenges that may make this potential methodology inappropriate in many situations.<\/p>\n<p>[47]\u00a0\u00a0\u00a0\u00a0\u00a0 Backup media may contain not just data regarding the database at issue, but also data from completely different systems as well.\u00a0 Separating this information will require additional time and expense and may be complicated by data privacy requirements, such as HIPAA, that require the enactment of significant security measures for the removal of data.[81]\u00a0 In addition to these costs, backup media must be restored, again requiring time, IT expertise, and suitable hardware to which the system image can be restored.[82]\u00a0 Finally, backup systems are far from perfect and failure rates, while not as high as they have been even in the recent past, are still in the words of a highly-respected industry analyst, \u201cnot acceptable.\u201d[83]<\/p>\n<h4 style=\"padding-left: 60px\"><b>3.\u00a0 Extracting Select Information from the Database<\/b><\/h4>\n<h4 style=\"padding-left: 90px\"><b>i.\u00a0 All Fields\/Data<\/b><\/h4>\n<p>[48]\u00a0\u00a0\u00a0\u00a0\u00a0 A more selective and thus more efficient alternative to collecting an entire repository is extracting the substantive data from the system and exporting it into a generic data format that can be read by multiple databases.\u00a0 The success of data collection using this methodology is relatively simple to test, using one of several established techniques.\u00a0 In addition, if the extraction process is handled according to IT industry standard practices and properly documented, authentication should also be relatively straightforward.\u00a0 Capturing a full set of the underlying data permits a case team to defer filtering and culling decisions to a later date, pushing back some expense until it is truly necessary.<\/p>\n<p>[49]\u00a0\u00a0\u00a0\u00a0\u00a0 Collecting database information through data extraction has some drawbacks.\u00a0 As with other techniques that capture the entire data set, much of what is collected will be irrelevant and will need to be filtered out before any review or production.\u00a0 This can be a lengthy, disruptive, and expensive process.\u00a0 It is important to note that extracting the complete data set does not mean that all of the capabilities of the original database will be available.\u00a0 Much of the value of many database systems stems from the <i>computed values<\/i> and analysis obtained by applying algorithms to source data.\u00a0 Capturing raw data alone is often not adequate to collect this high-value relational information as well.[84]\u00a0 The full extract, transform, and load process may be required to derive potentially critical information.<\/p>\n<h4 style=\"padding-left: 90px\"><b>ii.\u00a0 Selected Fields<\/b><\/h4>\n<p>[50]\u00a0\u00a0\u00a0\u00a0\u00a0 Because databases typically track much more information than is relevant to a particular legal matter, it may be possible to extract select information stored within it.\u00a0 Such selection can be applied along two axes: (1) limiting data extraction to a subset of database records and selecting them through an appropriate search query; and (2) limiting data extraction to only a subset of fields within a database record.\u00a0 Often, both limitations are applied in the same export.\u00a0 This approach has clear advantages in terms of cost, data volume, and amount of time required to complete the requested data extraction.\u00a0 However, by the same token, leaving behind some of the validating information found in a database field may make the extracted information more difficult to authenticate.<\/p>\n<p>[51]\u00a0\u00a0\u00a0\u00a0\u00a0 Identifying and extracting the relevant data depends on three things: (1) knowledge of the system; (2) understanding of the matter; and (3) skill at creating queries.\u00a0 Deficiencies in any one of these areas may complicate this effort.\u00a0 In addition, because not all of the data in a database is collected using this methodology, there is some risk if the database has an information purging function built into it.\u00a0 It may not be possible to fix mistakes if the initial selection criteria turn out to be incomplete.\u00a0 Fortunately, when cooperation exists between all participants and parties in the process, this collection methodology can be both efficient and cost-effective for everyone.<\/p>\n<h4 style=\"padding-left: 90px\"><b>iii.\u00a0 Sample Fields (and Potentially Reiterations as Needed)<\/b><\/h4>\n<p>[52]\u00a0\u00a0\u00a0\u00a0\u00a0 When the existence or non-existence of potentially relevant information is an open question, a final form of data extraction is to export sample database records.\u00a0 The process can be repeated reiteratively, even incorporating suggestions from the requesting parties.\u00a0 Properly conducted, this approach may permit a structured data repository to be dismissed as a source of potentially relevant information or it may hone the criteria required to identify and extract appropriate information.\u00a0 Either way, approaching such an investigation cooperatively, rather than unilaterally, may enhance the defensibility of this approach.[85]<\/p>\n<p>[53]\u00a0\u00a0\u00a0\u00a0\u00a0 Selected sampling incorporates the risk factors that arise when extracting only select information from a database.\u00a0 This approach adds a fourth potential failure point: the need for competence in generating appropriate sample sets and testing them for potential relevance.\u00a0 Because of the highly selective nature of this approach, rigorous documentation is required to answer questions that may arise later as to the adequacy of how this methodology was applied.<\/p>\n<h4 style=\"padding-left: 60px\"><b>4.\u00a0 Reports<\/b><\/h4>\n<h4 style=\"padding-left: 90px\"><b>i.\u00a0 Using Existing Reports<\/b><\/h4>\n<p>[54]\u00a0\u00a0\u00a0\u00a0\u00a0 Existing (<i>i.e<\/i>., \u201ccanned\u201d) database reports that are used for business purposes can be a useful first step for collecting structured data.\u00a0 First, the total data volume will be much lower than other methods unless the reports are themselves massive.\u00a0 However, as Comment 1F of the <i>Sedona Database Principles<\/i> highlights, even voluminous reports may still be appropriate to produce even with the inclusion of additional non-responsive information, as this could be the easiest, least expensive, and least burdensome way to obtain and produce the information so long as the producing party is not doing so for any improper purpose.[86]\u00a0 Second, existing reports were created and generated for business purposes and thus have typically been \u201cpre-validated.\u201d\u00a0 The accuracy of the information presented has been accepted as accurate and reliable as the basis for business decisions.[87]\u00a0 This can greatly simplify post-production validation and authentication.\u00a0 Third, these reports are typically minimally intrusive for an organization.\u00a0 The report templates and underlying queries have already been created and used in the ordinary course of business so no custom workflow must be developed.\u00a0 Fourth, especially with respect to Cloud-based\/SaaS type proprietary systems, reports may be the only way to retrieve data from a system.<\/p>\n<p>[55]\u00a0\u00a0\u00a0\u00a0\u00a0 Unfortunately, the use of existing reports is not a perfect collection solution.\u00a0 These reports were designed for specific business needs, not the needs specific to a legal dispute.\u00a0 For this reason, existing reports rare<br \/>\nly provide the information that is specifically requested.\u00a0 They typically provide too much or too little.\u00a0 A troubling problem, and one that is less well understood, is the fact that reports tend to not be \u201cpure\u201d output from the system.\u00a0 Many database reports are compilations and aggregations of information that are more than raw information output from stored information.\u00a0 Instead, this raw information may be added, reformatted, or otherwise \u201ctweaked\u201d from the pure source information in the database, sometimes to the point of showing significant deviation from source information.\u00a0 For purposes of validation and authentication, this can create obvious problems.<\/p>\n<p>[56]\u00a0\u00a0\u00a0\u00a0\u00a0 Often, requesting parties do not automatically accept database reports in lieu of direct discovery of the source database.\u00a0 In addition, it would be unwise to assume that the courts will side with the producing party over this issue without first examining the underlying facts leading to the creation of specific reports.[88]<\/p>\n<h4 style=\"padding-left: 90px\"><b>ii.\u00a0 Creating Customized Reports<\/b><\/h4>\n<p>[57]\u00a0\u00a0\u00a0\u00a0\u00a0 Another option for data extraction from structured data repositories is to design a custom report.\u00a0 Custom reports provide greater flexibility than existing reports due to their ability to be limited to relevant data, data fields, and time periods.\u00a0 Custom reports also help to limit inadvertent disclosure of irrelevant data and can even be used on privileged, confidential, or protected personally identifiable information.<\/p>\n<p>[58]\u00a0\u00a0\u00a0\u00a0\u00a0 As a word of caution, not every system allows for the creation of custom reports, and even when this functionality is available, it may be difficult or expensive to use.\u00a0 Custom reports may face a greater evidentiary hurdle than canned reports used in day-to-day business operations.\u00a0 However, courts have been somewhat more sympathetic to production objections based on the undue burden of creating expensive custom database reports to comply with incoming discovery requests.[89]<\/p>\n<h4 style=\"padding-left: 60px\"><b>5.\u00a0 TIFF Image Snapshots<\/b><\/h4>\n<p>[59]\u00a0\u00a0\u00a0\u00a0\u00a0 An older, and now less commonly accepted, way to produce structured data is to capture database output sent to the monitor or to reports and to render these \u201csnapshots\u201d to TIFF image.\u00a0 This creates an easily preserved form that can be Bates-stamped and for which authenticity can easily be stipulated.[90]\u00a0 While appropriate in some situations, this production method has fallen out of favor compared to other alternatives since it tends to reduce the fielded nature of the underlying data, thereby turning structured data into flat, inflexible unstructured documents that may or may not contain searchable text.\u00a0 That being said, certain database systems have such limited data output capabilities that capture of data in this manner may be one of the only options currently available.<\/p>\n<h4 style=\"padding-left: 60px\"><b>6.\u00a0 Direct Access to the System<\/b><\/h4>\n<p>[60]\u00a0\u00a0\u00a0\u00a0\u00a0 A final method for producing information from a database is to simply let the requesting party or its expert have direct access to that system to run its own queries or reports.\u00a0 However, most litigants highly disfavor this method as it allows the opposing party potential access to privileged and confidential information within the database.\u00a0 Courts that have addressed this situation have tended to be receptive to such concerns, requiring that limits be set.[91]\u00a0 This direct access approach also has significant potential to disrupt in-house IT infrastructure and staff who are likely to be unhappy at opening a controlled organization\u2019s asset to interlopers.\u00a0 Indeed, the Committee Notes to the 2006 Amendments to FRCP 34 make it quite clear:<\/p>\n<p style=\"padding-left: 30px\"><em>The addition of testing and sampling to Rule 34(a) with regard to documents and electronically stored information is not meant to create a routine right of direct access to a party&#8217;s electronic information system, although such access might be justified in some circumstances.\u00a0 Courts should guard against undue intrusiveness resulting from inspecting or testing such systems.[92]<\/em><\/p>\n<p>[61]\u00a0\u00a0\u00a0\u00a0\u00a0 In addition, granting outsiders access to data repositories containing certain personally identifiable information may violate data privacy laws and create significant (albeit unrelated) liability for the producing party.\u00a0 For these reasons, direct access to databases and other such systems tends to be granted over objection \u201conly in extraordinary circumstances.\u201d [93]<\/p>\n<p>[62]\u00a0\u00a0\u00a0\u00a0\u00a0 No matter what process is used to preserve and collect a database, proper documentation and testing is critical as many of these processes are complicated and mistakes can occur.\u00a0 Proper documentation and a record of testing will help to demonstrate good faith efforts if these procedures are later called into question.[94]<\/p>\n<h3 style=\"padding-left: 30px\"><b>C.\u00a0 ECA and Processing<\/b><\/h3>\n<p>[63]\u00a0\u00a0\u00a0\u00a0\u00a0 Once the data has been extracted from its repository, it typically undergoes further transformation so that it can be used in the investigation or litigation context prior to attorneys\u2019 review for substance.\u00a0 For loose documents, litigants typically apply early case assessment techniques, such as key word or concept filtering, to reduce the data volume.[95]\u00a0 Unfortunately, such techniques do not apply well to structured data, as this information is largely centered around transactions rather than words and phrases.\u00a0 Properly processing and limiting the volume of such systems can instead profile the transactions using specific fields, dates, and general ledger codes.\u00a0 A strong understanding of the system at hand becomes even more important in such situations.<\/p>\n<p>[64]\u00a0\u00a0\u00a0\u00a0\u00a0 Traditional culling methods may be more helpful when the extracted data includes free-form text entry fields such as \u201ccomment\u201d fields.\u00a0 Even here, though, because the unified extracted data exists as a single mass of (fielded) information, culling this glob of information can raise evidentiary challenges unless all changes are well documented and ideally, negotiated at least in principle with the requesting party.<\/p>\n<h3 style=\"padding-left: 30px\"><b>D.\u00a0 Review and Analysis<\/b><\/h3>\n<p>[65]\u00a0\u00a0\u00a0\u00a0\u00a0 Once the data has been processed and preliminary analytics have been applied, it may still need to be reviewed for responsiveness and privilege.\u00a0 Some structured data can be managed within standard review platforms, especially flat-file reports and data tables rendered as Microsoft Excel spreadsheets.\u00a0 On the other hand, data extracted from enterprise-grade relational databases cannot be loaded into a review platform with any genuine hope of validly reviewing this information.\u00a0 As described in the <i>Sedona Database Principles<\/i>:<\/p>\n<p style=\"padding-left: 30px\"><em>Analyzing email messages and discrete electronic files typically involves a team (sometimes a large team) of reviewers and takes place through a document review platform.\u00a0 Such review and analytical tools, however, are a poor fit for the matrices of information found in tables of extracted database information.\u00a0 Instead, review of this information may require technically sophisticated analysts to query the data and extract the meaning of its aggregated information.[96]<\/em><\/p>\n<p>[66]\u00a0\u00a0\u00a0\u00a0\u00a0 A more straightforward approach to reviewing structured data looks not to the data\u2019s abstract relevance, but instead to the significance of its data values.\u00a0 Certain field information, such as protected private information, may be redacted or stripped, but this is the closest analogy to the parallel review process that takes place in a document review platform.\u00a0 Otherwise, extracted data is manipulated, queried, and explored.\u00a0 In addition, once protected and privileged data fields are removed from extracted structured data, no further attorney review of individual data fields is typically required.<\/p>\n<p>[67]\u00a0\u00a0\u00a0\u00a0\u00a0 When the content of individual data fields, such as notes or memo fields, require attorney review, the review par<br \/>\nadigm must be further adjusted.\u00a0 Such a review is complicated by the fact that the information that requires review tends to be stored in a structured manner, but contains unstructured data, such as free text that lacks parameter constraints on length or format.\u00a0 Technical specialists are typically enlisted to develop secure web-based database review tools that present this information in a reviewable format for redaction purposes.\u00a0 Certain profiling and culling methods can be employed to reduce the overall volume of information that requires attorney review, but generally, some \u201ceyes-on\u201d attorney review will be required.<\/p>\n<h3 style=\"padding-left: 30px\"><b>E.\u00a0 Production<\/b><\/h3>\n<p>[68]\u00a0\u00a0\u00a0\u00a0\u00a0 Extraction and Transformation processes largely set the production of structured data.\u00a0 Information that has been shed as a by-product of transformation processes may now be non-replicable since many forms of extraction do not allow conversion back \u201cupstream.\u201d\u00a0 You cannot, for example, extract data as reports and then reconstitute the data to produce it as a complete database.\u00a0 Such is the reason that Sedona Database Principle 6: Form of Production reminds us that: \u201cThe way in which a requesting party intends to use database information is an important factor in determining an appropriate format of production.[97]\u00a0 Comment 6A of the <i>Sedona Database Principles<\/i> takes this even further by underscoring that \u201cit may be impossible for a responding party to take appropriate steps to provide database information in a reasonably useful format if it has no idea how the requesting party intends to use it.\u201d[98]<\/p>\n<p>[69]\u00a0\u00a0\u00a0\u00a0\u00a0 Even if the parties do not avail themselves of the warnings of the <i>Sedona Principles<\/i> and the <i>Sedona Database Principles<\/i> and decline to work together to determine a reasonably usable production format, this lack of agreement does not mean that parties are free to produce data in any format they choose.\u00a0 FRCP 34(b)(2)(E) requires:<\/p>\n<p style=\"padding-left: 30px\"><em>(E) Producing the Documents or Electronically Stored Information.\u00a0 Unless otherwise stipulated or ordered by the court, these procedures apply to producing documents or electronically stored information:<\/em><\/p>\n<p style=\"padding-left: 60px\"><em>(i) A party must produce documents as they are kept in the usual course of business or must organize and label them to correspond to the categories in the request;<\/em><\/p>\n<p style=\"padding-left: 60px\"><em>(ii) If a request does not specify a form for producing electronically stored information, a party must produce it in a form or forms in which it is ordinarily maintained or in a reasonably usable form or forms; and<\/em><\/p>\n<p style=\"padding-left: 60px\"><em>(iii) A party need not produce the same electronically stored information in more than one form.[99]<\/em><\/p>\n<p>[70]\u00a0\u00a0\u00a0\u00a0\u00a0 Courts have shown that they will be alert to production formats that are not usable.[100]\u00a0 Courts can also order parties to produce data in particular formats even if it requires the creation of entirely new data sets.[101]\u00a0 However, at the same time, the full cost of producing structured data does not always fall entirely on the producing party.\u00a0 In some circumstances, a requesting party may be required to bear the burden and expense of some degree of transformation of the data from the producing party so long as the format of the production was in fact reasonable.[102]<\/p>\n<p>[71]\u00a0\u00a0\u00a0\u00a0\u00a0 The <i>Sedona Principles<\/i> echo the concerns of the courts in Principle 12: Form of Production and Metadata:<\/p>\n<p style=\"padding-left: 30px\"><em>Absent party agreement or court order specifying the form or forms of production, production should be made in the form or forms in which the information is ordinarily maintained or in a reasonably usable form, taking into account the need to produce reasonably accessible metadata that will enable the receiving party to have the same ability to access, search, and display the information as the producing party where appropriate or necessary in light of the nature of the information and needs of the case.[103]<\/em><\/p>\n<p>[72]\u00a0\u00a0\u00a0\u00a0\u00a0 Difficulties can arise when an opposing party requests that structured data be produced in \u201cnative format\u201d\u2014that is, the original file format in which producing party keeps the ESI.\u00a0 Courts have sometimes shown an un-nuanced willingness to enforce general demands for native format production if it is properly and timely requested, or even if that is lacking, if good cause can be shown[104] or absent a showing of undue burden or hardship.[105]\u00a0 At times, the courts have even required such native file productions from database systems.[106]\u00a0 Many parties indirectly request this by requesting production of \u201cthe entire database.\u201d[107]<\/p>\n<p>[73]\u00a0\u00a0\u00a0\u00a0\u00a0 Unfortunately, a \u201cnative file\u201d production for structured data can present a number of difficult and unique problems.\u00a0 First, and most obvious, the proprietary database format in which relevant data is stored may not be readable and thus, not \u201creasonably usable\u201d to the requesting party.\u00a0 Handing over to the other side a complete copy of a database system, particularly a world-class enterprise system, is also not a sufficient solution.\u00a0 The recipient may well need to obtain a licensed copy of the system\u2014a potentially very expensive proposition in the case of high-end database systems\u2014or a near impossible proposition in the case of legacy or obsolete systems that are no longer commercially available (even as they remain protected by copyright and license restrictions from free copying).\u00a0 Even if a license for the system can be obtained, installation of the system could take weeks or months and success is not always a given.[108]\u00a0 Finally, even once such hurdles are successfully overcome, the very first use or view of a copied database system is likely to change the information therein, as such systems typically have tracking capabilities that are difficult or even impossible to turn off, making the copy no longer an accurate copy.[109]<\/p>\n<p>[74]\u00a0\u00a0\u00a0\u00a0\u00a0 For all of these reasons, more transformative production formats, which change the data from the way it is stored in the ordinary course of business, have become a commonly accepted discovery practice.[110]\u00a0 In addition, a strong argument can be made that the fielded nature of the raw data, not the proprietary container in which it is stored, is the essential element that provides \u201cnative format\u201d flexibility to this information.\u00a0 If this argument is accepted, further transformation of the data may provide increased accessibility without compromising essential functionality.<\/p>\n<p><b>\u00a0<\/b><\/p>\n<h3 align=\"center\"><b>VI.\u00a0 Issues Beyond the EDRM<\/b><\/h3>\n<p>[75]\u00a0\u00a0\u00a0\u00a0\u00a0 Because structured data does not fit squarely within an EDRM that was implicitly designed for unstructured data types, it should come as no surprise that additional issues often arise in working with structured data in discovery.<\/p>\n<h3 style=\"padding-left: 30px\"><b>A.\u00a0 Custody and Control<\/b><\/h3>\n<p>[76]\u00a0\u00a0\u00a0\u00a0\u00a0 A respondent in discovery is only required to turn over what is in their possession, custody, and control.[111]\u00a0 This obligation extends to traditional materials and ESI alike as well as to unstructured and structured data alike.\u00a0 Complex databases, however, can challenge the issue of where data is stored and the extent to which it is \u201cowned\u201d by the content creator.\u00a0 For example, a database may be housed entirely within a corporation and serviced by company IT professionals, so there would be no possession, custody, or control issue.\u00a0 However, when the database is provided by a service provider, questions about information ownership can and do arise.\u00a0 The licensing provisions for many Cloud-based SaaS providers hold that while information entered into the outsourced database may be the exclusive property of the database service client, many of the internal database elements that create relationships between this client provided data are proprietary to the point that a client does not have permission to view these<br \/>\n relationships, much less export them in response to a discovery request.[112]\u00a0 As a consequence, the \u201cowner\u201d of information in these systems\u2014the SaaS client\u2014may not have custody or control over a portion of the ESI that it would have to provide if it hosted the database itself.<\/p>\n<h3 style=\"padding-left: 30px\"><b>B.\u00a0 Verifying that the Data Collected is Accurate<\/b><\/h3>\n<p>[77]\u00a0\u00a0\u00a0\u00a0\u00a0 Structured data has the unusual property of appearing accurate and precise, even if the substantive information that the database reports is riddled with errors.\u00a0 This issue can occur because the precision of a database search query or report is separate and distinct from the way in which the source data was created or entered into the system.\u00a0 For example, operators at a call center may be asked to enter their recollections and remarks about customer questions and complaints.\u00a0 This information is likely entered quickly as the operators focus on handling as many calls as possible during their shift and it may contain errors.\u00a0 Yet, when this same information appears in a database report, it is likely to have the appearance of an accurate and truthful statement.<\/p>\n<p>[78]\u00a0\u00a0\u00a0\u00a0\u00a0 Sedona Database Principle 5: Data Integrity, Authenticity, and Admissibility considers this issue: \u201cVerifying information that has been correctly exported from a larger database or repository is a separate analysis from establishing the accuracy, authenticity, or admissibility of the substantive information contained within the data.\u201d[113]\u00a0 Thus, in working with structured data, many practitioners have found it useful to separate these two competing questions about \u201caccuracy.\u201d\u00a0 It is possible to validate the accuracy of a mechanical data export.\u00a0 For example, certain reference fields or reference values can be exported with the substantive data and those values verified against the source information in the database itself.\u00a0 Even something as simple as comparing the number of database records exported against the number of database records returned by a search query is a step in this direction.<\/p>\n<p>[79]\u00a0\u00a0\u00a0\u00a0\u00a0 Conversely, practitioners can reserve the right to further challenge the accuracy of the information contained within a structured data repository.\u00a0 In evidentiary terms, the authenticity of the information\u2014that is to say, the information was accurately exported from a database\u2014can be the subject of a stipulation, but the truthful nature of the information remains subject to standard challenges as to hearsay and general reliability.[114]<\/p>\n<h3 style=\"padding-left: 30px\"><b>C.\u00a0 Validating Structured Data so that It Can Be Admissible as Substantive Evidence<\/b><\/h3>\n<p>[80]\u00a0\u00a0\u00a0\u00a0\u00a0 Validating structured data is an important consideration when working with this form of ESI.\u00a0 As noted previously, many practitioners are able to find common ground and negotiate a stipulation that ESI has been accurately exported or copied from the source database.\u00a0 Authenticity can be mechanically established even though the exported form of the data is unlikely to be identical to the way that the structured data was maintained inside a larger database.\u00a0 The <i>Sedona Database Principles<\/i> recognize and address this problem, in Principle 4: Validation: \u201cA responding party must use reasonable measures to validate ESI collected from database systems to ensure completeness and accuracy of the data acquisition.\u201d[115]<\/p>\n<p>[81]\u00a0\u00a0\u00a0\u00a0\u00a0 The larger issue, though, is finding a consistent workflow for establishing the reliability of structured data so that it may be admissible for the truth of the information contained therein.\u00a0 Because structured data is typically exchanged in the form of data exports or reports, at least one court has found that the business record exception to the hearsay rule is inapplicable as grounds for admitting this information for the truth of the matter asserted.[116]\u00a0 In the case of <i>Vinhee<\/i>, the court required a detailed showing of how information was entered into a database, including all efforts to identify and correct errors.[117]\u00a0 The court further required additional foundation about how the underlying database was managed.[118]<\/p>\n<p>[82]\u00a0\u00a0\u00a0\u00a0\u00a0 A majority of other courts have imposed a less onerous set of requirements to admit extracted structured data for the truth of the matter concerned.[119]\u00a0 A key point of argument remains the degree to which substantive information entered into a database has been validated as accurate near or at the time of its creation as structured data.\u00a0 Systems that include such validation will have their information more easily ruled admissible than more open and less regulated databases.\u00a0 In such cases, courts may begin to look at some of the <i>Vinhee<\/i> factors as additional extrinsic evidence required to lay a sufficient evidentiary foundation.<\/p>\n<h3 style=\"padding-left: 30px\"><b>D.\u00a0 Privacy<\/b><\/h3>\n<p>[83]\u00a0\u00a0\u00a0\u00a0\u00a0 There are many types of database systems that contain vast amounts of private and personally-identifiable information (\u201cPII\u201d) such as HR systems, financial systems, healthcare systems, and customer transaction systems to name a few.\u00a0 PII resides in some unexpected databases that most would not expect to contain confidential PII.\u00a0 Web-logging systems, for example, capture unique IP addresses that could be used to track down the identity and location of users.\u00a0 Such protected information will need to be identified and redacted prior to release of this data to a requesting party.\u00a0 On the plus side, the same analytical measures that can assist with the extraction of the data can often also be used to locate and redact the confidential data, whether by removing it or replacing it with dummy data.\u00a0 However, while such systems cannot always be perfect, many privacy laws are written with such perfection in mind so as to be rather unforgiving even as towards minor violations.\u00a0 Thus, the parties are advised to carefully discuss putting into place protocols, potentially including protective orders, against the possibility of the inadvertent disclosure of PII.[120]<\/p>\n<p>[84]\u00a0\u00a0\u00a0\u00a0\u00a0 Unfortunately, that is not the end to the potential problems.\u00a0 Because database systems tend to be distributed, portions of a system or systems to which it connects may well physically be located across jurisdictions, such as the European Union, that have strict privacy regulations.[121]\u00a0 Other jurisdictions may not be concerned with the physical location of the data, but instead as to whether the data subjects\u2014those whose information has been collected and stored\u2014live within that jurisdiction.[122]\u00a0 The penalties for violations of these laws and regulations can be severe, so careful legal consideration of the issues before taking action is well advised.[123]<\/p>\n<p>&nbsp;<\/p>\n<h3 align=\"center\"><b>VII.\u00a0 Conclusion<\/b><\/h3>\n<p>[85]\u00a0\u00a0\u00a0\u00a0\u00a0 Dealing with structured data in e-discovery is something that should neither be ignored nor treated lightly.\u00a0 A case team may be required to handle structured data because an investigator, regulator or the opposing party requests it, or a case team may need to deal with it just to try to understand and prove its case.\u00a0 Situations will arise where the proper expert use of structured data is the best or the only way \u201cto follow the money\u201d and figure out what actually happened.\u00a0 When that situation arises, case teams are likely to need expert assistance to handle the myriad of issues both technical and legal, within the EDRM, and without.<\/p>\n<p>&nbsp;<\/p>\n<h3 align=\"center\"><b>Appendix<\/b><\/h3>\n<h4 align=\"center\"><b>ETL As Applied to the EDRM Model<\/b><\/h4>\n<p align=\"center\"><b>\u00a0<a href=\"http:\/\/jolt.richmond.edu\/files\/2013\/04\/Simon-Appendix.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone  wp-image-1244\" alt=\"Simon Appendix\" src=\"http:\/\/jolt.richmond.edu\/files\/2013\/04\/Simon-Appendix.png\" width=\"571\" height=\"271\" \/><\/a><\/b><\/p>\n<p>*Derived from the Electronic Discovery Reference Model v 2.0, which are used under See Creative Commons Attribution 3.0 United States License. | \u00a9 2005-2012 EDRM, LLC.<\/p>\n<p><b><br \/>\n <\/b><\/p>\n<h3 align=\"center\"><b>The Sedona Conference<\/b><b><sup>\u00ae<\/sup><\/b><b> Database Principles Addressing the Preservation and Production of Databases and Database Information in Civil Litigation<\/b>[124]<\/h3>\n<h4 style=\"padding-left: 30px\"><b>Principle 1: Scope of Discovery<\/b><\/h4>\n<p>Absent a specific showing of need or relevance, a requesting party is entitled only to database fields that contain relevant information, not the entire database in which the information resides or the underlying database application or database engine.<\/p>\n<h4 style=\"padding-left: 30px\"><b>Principle 2: Accessibility and Proportionality<\/b><\/h4>\n<p>Due to the differences in the way that information is stored or programmed into a database, not all information in a database may be equally accessible, and a party\u2019s request for such information must be analyzed for relevance and proportionality.<\/p>\n<h4 style=\"padding-left: 30px\"><b>Principle 3: Use of Test Queries and Pilot Projects<\/b><\/h4>\n<p>Requesting and responding parties should use empirical information, such as that generated from test queries and pilot projects, to ascertain the burden to produce information stored in databases and to reach consensus on the scope of discovery.<\/p>\n<h4 style=\"padding-left: 30px\"><b>Principle 4: Validation<\/b><\/h4>\n<p>A responding party must use reasonable measures to validate ESI collected from database systems to ensure completeness and accuracy of the data acquisition.<\/p>\n<h4 style=\"padding-left: 30px\"><b>Principle 5: Data Integrity, Authenticity, and Admissibility<\/b><\/h4>\n<p>Verifying information that has been correctly exported from a larger database or repository is a separate analysis from establishing the accuracy, authenticity, or admissibility of the substantive information contained within the data.<\/p>\n<h4 style=\"padding-left: 30px\"><b>Principle 6: Form of Production<\/b><\/h4>\n<p>The way in which a requesting party intends to use database information is an important factor in determining an appropriate format of production.<\/p>\n<div>\n<p>&nbsp;<\/p>\n<hr align=\"left\" size=\"1\" width=\"33%\" \/>\n<div>\n<p>* Conrad Jacoby is a Senior Attorney at Winston &amp; Strawn LLP, where his practice focuses on e-discovery issues and litigation information management.\u00a0 Since 2009, he has served as the founding Editor-in-Chief of <i>The Sedona Conference\u00ae Database Principles: Addressing the Preservation &amp; Production of Databases &amp; Database Information in Civil Litigation<\/i>.\u00a0 The opinions expressed are those of the authors and do not necessarily reflect the views of their respective firms or clients. This article is for general information purposes and is not intended to be and should not be taken as legal advice<\/p>\n<p>** Jim Vint is a Managing Director at Navigant Consulting, Inc. and runs the Structured Data and Development team within the Technology Solutions group.\u00a0 He focuses on discovery and disclosure of non-traditional ESI data sources including structured databases.\u00a0 His clients include global organizations facing regulatory investigations, cross border discovery issues, and general commercial disputes.<\/p>\n<p>*** Michael Simon is Director of Strategic Development for Navigant Consulting, Inc.\u00a0 Michael, a former practicing attorney, has worked with and counseled clients regarding e-discovery issues and best practices for over a decade.\u00a0 He frequently lectures on e-discovery, legal technology and Internet law in venues across the United States, including Tufts University, where he has taught as a visiting lecturer.<\/p>\n<p>&nbsp;<\/p>\n<p>[1] <i>See<\/i> The Sedona Conference<i>\u00ae<\/i>, The Sedona Conference<i>\u00ae<\/i> Glossary: E-Discovery and Information Management 52 (Sherry B. Harris ed., 3d ed. 2010) [hereinafter <i>Sedona Glossary<\/i>].<\/p>\n<\/div>\n<div>\n<p>[2] <i>See<\/i> <i>id.<\/i> at 49.<\/p>\n<\/div>\n<div>\n<p>[3] <i>See<\/i> <i>id.<\/i> at 13, 49, 52 (definitions of \u201cdatabase,\u201d \u201cdatabase management system,\u201d \u201cstructured data,\u201d and \u201cunstructured data\u201d).<\/p>\n<\/div>\n<div>\n<p>[4] Fed. R. Civ. P. 34(a)(1)(A) (emphasis added).<\/p>\n<\/div>\n<div>\n<p>[5] <i>See <\/i>The Sedona Conference<i>\u00ae<\/i>, The Sedona Conference<i>\u00ae<\/i> Database Principles: Addressing the Preservation &amp; Production of Databases &amp; Database Information in Civil Litigation 21 (Conrad J. Jacoby et al. eds., 2011) [hereinafter <i>Sedona Database Principles<\/i>].<\/p>\n<\/div>\n<div>\n<p>[6] <i>See<\/i> The Sedona Conference<i>\u00ae<\/i>, The Sedona Principles: Best Practices Recommendations &amp; Principles for Addressing Electronic Document Production 30 (Jonathan M. Redgrave et. al ed., 2d eds. 2007) [hereinafter <i>Sedona Principles<\/i>].<\/p>\n<\/div>\n<div>\n<p>[7] <i>See Sedona Database Principles<\/i>, <i>supra<\/i> note 5, at ii, 8.<\/p>\n<\/div>\n<div>\n<p>[8] <i>See id.<\/i> at ii.<\/p>\n<\/div>\n<div>\n<p>[9] <i>See id<\/i> at ii, 8-9.<\/p>\n<\/div>\n<div>\n<p>[10] Nexsan Corp., Registration Statement (Form S-1), at 61 (Jan. 25, 2011), <i>available at <\/i>http:\/\/www.sec.gov\/Archives\/edgar\/data\/1133448\/000104746911000283\/a2200385zex-99_2.htm.<\/p>\n<\/div>\n<div>\n<p>[11] <i>See Information Retention and eDiscovery Survey Global Findings<\/i>, Symantec 1, 8 (2011), https:\/\/www4.symantec.com\/mktginfo\/whitepaper\/InfoRetention_eDiscovery_Survey_Report_cta54646.pdf.<\/p>\n<\/div>\n<div>\n<p>[12] <i>Id.<\/i><\/p>\n<\/div>\n<div>\n<p>[13] <i>In re <\/i>eBay Seller Antitrust Litig., No. C 07-1882 JF (RS), 2009 WL 3613511, at *1 (N.D. Cal. Oct. 28, 2009).<\/p>\n<\/div>\n<div>\n<p>[14] <i>Id.<\/i><\/p>\n<\/div>\n<div>\n<p>[15] <i>Id.<\/i> at *2.<\/p>\n<\/div>\n<div>\n<p>[16] <i>Id.<\/i><\/p>\n<\/div>\n<div>\n<p>[17] <i>See id.<\/i><\/p>\n<\/div>\n<div>\n<p>[18] <i>See In re eBay Seller Antitrust Litig.<\/i>, 2009 WL 3613511, at *3.<\/p>\n<\/div>\n<div>\n<p>[19] <i>In re<\/i> Lowe&#8217;s Cos., 134 S.W.3d 876, 877 (Tex. App. 2004).<\/p>\n<\/div>\n<div>\n<p>[20] <i>See id. <\/i>at 877.<\/p>\n<\/div>\n<div>\n<p>[21] <i>Id.<\/i> at 878.<\/p>\n<\/div>\n<div>\n<p>[22] <i>See id.<\/i> at 880.<\/p>\n<\/div>\n<div>\n<p>[23] Procter &amp; Gamble Co. v. Haugen<i>,<\/i> 427 F.3d 727, 730, 732-37 (10th Cir. 2005).<\/p>\n<\/div>\n<div>\n<p>[24] <i>Id.<\/i> at 731.<\/p>\n<\/div>\n<div>\n<p>[25] <i>Id.<\/i> at 731-32.<\/p>\n<\/div>\n<div>\n<p>[26] <i>Id<\/i>. at 731.<\/p>\n<\/div>\n<div>\n<p>[27] <i>Id<\/i>.<\/p>\n<\/div>\n<div>\n<p>[28] <i>See<\/i> <i>Procter &amp; Gamble Co.<\/i>, 427 F.3d at 732-33, 735-37.<\/p>\n<\/div>\n<div>\n<p>[29] <i>See id.<\/i> at 739.<\/p>\n<\/div>\n<div>\n<p>[30] <i>See id.<\/i><\/p>\n<\/div>\n<div>\n<p>[31] <i>See id<\/i>.\u00a0 In 2013, it may seem unbelievable that a major corporation, like P&amp;G would be unable to afford sufficient storage capacity for this data.\u00a0 However, when this case was decided in 1995, the court recognized $30 million as a prohibitive storage cost.\u00a0 <i>See id.<\/i><\/p>\n<\/div>\n<div>\n<p>[32] <i>Id.<\/i> at 739-41.<\/p>\n<\/div>\n<div>\n<p>[33] <i>See<\/i> Powerhouse Marks, L.L.C. v. Chi Hsin Impex, Inc., No. Civ.A.04CV73923DT, 2006 WL 83477, at *1-2 (E.D. Mich. Jan. 12, 2006).<\/p>\n<\/div>\n<div>\n<p>[34] <i>See id.<\/i> at *1, *3.<\/p>\n<\/div>\n<div>\n<p>[35] <i>Id.<\/i> at *3.<\/p>\n<\/div>\n<div>\n<p>[36] <i>Id.<\/i><\/p>\n<\/div>\n<div>\n<p>[37] <i>See id.<\/i> at *4.<\/p>\n<\/div>\n<div>\n<p>[38] EEOC<i> <\/i>v. Supervalu, Inc., No. 09 CV 5637, 2010 WL 5071196, at *1 (N.D. Ill. Dec. 7, 2010).<\/p>\n<\/div>\n<div>\n<p>[39] <i>Id<\/i>. at *6-7.<\/p>\n<\/div>\n<div>\n<p>[40] <i>Id<\/i>. at *6.<\/p>\n<\/div>\n<div>\n<p>[41] <i>Id.<\/i> at *7.<\/p>\n<\/div>\n<div>\n<p>[42] <i>Id.<\/i><\/p>\n<\/div>\n<div>\n<p>[43] <i>Supervalu, Inc.<\/i>, 2010 WL 5071196, at *8, *12.<\/p>\n<\/div>\n<div>\n<p>[44] <i>Sedona Database Principles<\/i>, <i>supra <\/i>note 5, at 4.<\/p>\n<\/div>\n<div>\n<p>[45] Courtney Fletcher &amp; Liam Ferguson, <i>E-Discovery: Remembering Forgotten Data<\/i>, Wall Street &amp; Tech. (Oct. 21, 2009), http:\/\/www.wallstreetandtech.com\/regulatory-compliance\/e-discovery-remembering-forgotten-data\/220900032.<\/p>\n<\/div>\n<div>\n<p>[46] <i>See<\/i> <i>Sedona Database Principles<\/i>, <i>supra <\/i>note 5, at 2, 6, 12, 17; <i>see also<\/i> Douglas Herman, <i>Digital Investigations \u2013 Where You Forgot To Look: Why Databases Often Are Overlooked When It Comes Time To Harvest Electronic Data<\/i>, Metro. Corp. Couns., (Aug. 2006), http:\/\/www.metrocorpcounsel.com\/pdf\/2006\/August\/22.pdf (\u201cTo extract data from a relational structure[,] such as a CRM or ERP database, requires specific expertise and a solid understanding<br \/>\n of the underlying bases of how these databases work.\u201d).<\/p>\n<\/div>\n<div>\n<p>[47] <i>Sedona Database Principles<\/i>, <i>supra <\/i>note 5, at 2.<\/p>\n<\/div>\n<div>\n<p>[48] <i>See<\/i> Rebman v. Follet Higher Educ. Grp., Inc., No. 6:06-CV-1476-ORL-28KRS, 2007 WL 1303031, at *3 (M.D. Fla. May 3, 2007) (Plaintiff\u2019s broad request for data from a database with over 200 million records denied by the court as overbroad; court ordered parties to meet and confer under Rule 26(f) to narrow the request and determine the need versus the burden on the defendant).<\/p>\n<\/div>\n<div>\n<p>[49] <i>Sedona Database Principles<\/i>, <i>supra <\/i>note 5, at 8 (quoting <i>Sedona Principles<\/i>, <i>supra <\/i>note 6, at 21).<\/p>\n<\/div>\n<div>\n<p>[50] <i>See<\/i> <i>id.<\/i> at 24.<\/p>\n<\/div>\n<div>\n<p>[51] <i>See, e.g.<\/i>, Ojeda-Sanchez v. Bland Farms, LLC, No. CV608-096, 2009 WL 2365976, at *3 (S.D. Ga. July 31, 2009) (requiring production of entire database as \u201cmetadata\u201d where the formulas within the system were relevant to the issues in a wage and hour class action); <i>see<\/i> <i>also<\/i> <i>Sedona Database Principles<\/i>, <i>supra <\/i>note 5, at 25 illus. iii.<\/p>\n<\/div>\n<div>\n<p>[52] <i>See, e.g.<\/i>, Goshawk Dedicated Ltd. v. Am. Viatical Servs., LLC, No. 1:05CV2343-RWS, 2007 WL 3492762, at *1 (N.D. Ga. Nov. 5, 2007) (requiring production of database in fraud and truth in lending case required despite respondent\u2019s claim that it was confidential and \u201cthe single greatest asset\u201d of the party because the accuracy of the data and algorithms therein was highly relevant to the claims and defenses of the case).<\/p>\n<\/div>\n<div>\n<p>[53] <i>Sedona Database Principles<\/i>, <i>supra <\/i>note 5, at 21.<\/p>\n<\/div>\n<div>\n<p>[54] <i>See id.<\/i> at 27-30.<\/p>\n<\/div>\n<div>\n<p>[55] <i>See id.<\/i> at 28.\u00a0 The problem of database systems designed for particular purposes, which are not accessible in the ways required for discovery, was specifically recognized by the Standing Committee of the Judicial Conference in its September 2005 Report Recommending the Adoption of the 2006 Amendments, as a potential form or not \u201creadily accessible\u201d ESI under Rule 26(b): \u201c[D]atabases that were designed to create certain information in certain ways and that cannot readily create very different kinds or forms of information.\u201d\u00a0 Report of Judicial Conference of the United States on Rules of Practice and Procedure C-42 (Sept. 2005), <i>available at <\/i>http:\/\/www.uscourts.gov\/uscourts\/RulesAndPolicies\/rules\/Reports\/ST09-2005.pdf [hereinafter <i>Judicial Conference Report<\/i>].<\/p>\n<\/div>\n<div>\n<p>[56] To optimize database performance, some database systems will only index portions of long, free-form text fields\u2014such as the first few hundred characters\u2014so that search results from such systems may not be complete.\u00a0 <i>See<\/i> <i>Sedona Database Principles<\/i>, <i>supra<\/i> note 5, at 17, 28.<\/p>\n<\/div>\n<div>\n<p>[57] Some database systems use \u201clook up\u201d tables or \u201cdrop down\u201d menus to create pre-defined data entry fields which contain information hard-coded into the system itself, not in any searchable fields.\u00a0 <i>See<\/i> <i>id<\/i>. at 28.<\/p>\n<\/div>\n<div>\n<p>[58] <i>See<\/i> <i>id<\/i>. at 29.\u00a0 With the increasing popularity of SaaS systems, such as Salesforce.com, the business user of a system may no longer have any access to a system beyond their usual user interface.\u00a0 <i>Id<\/i>.<\/p>\n<p>[59] <i>See<\/i> <i>id<\/i>.<i> <\/i>at 6 (IT departments are likely to require extensive and time-consuming testing of any third-party system that would be installed inside the corporation, especially if it would connect to a mission-critical system).<\/p>\n<\/div>\n<div>\n<p>[60] <i>See<\/i> <i>id<\/i>. at 29.<\/p>\n<\/div>\n<div>\n<p>[61]<i> See, e.g.<\/i>, Zurich Am. Ins. Co. v. Ace Am. Reinsurance Co.,<i> <\/i>No. 05 Civ. 9170 RMB JCF, 2006 WL 3771090 (S.D.N.Y. Dec. 22, 2006); Static Control Components, Inc. v. Lexmark Int\u2019l, Inc., No. 04-84-KSF, 2006 WL 897218 (E.D. Ky. Apr. 5, 2006).\u00a0 However, this does not mean that the courts will necessarily unreasonable requests.\u00a0 <i>See, e.g.<\/i>,<i> In re <\/i>Ex Parte Application of Apotex Inc<i>.<\/i>,<i> <\/i>No. M12-160, 2009 WL 618243 (S.D.N.Y. Mar. 9, 2009) (two weeks before scheduled trial, a party in patent litigation sent a broad subpoena for data to a competitor, involving data from over 30 years ago; court denied the request after the competitor demonstrated the difficulty of obtaining the data).<\/p>\n<\/div>\n<div>\n<p>[62] <i>See, e.g.<\/i>,<i> <\/i>Cartel Asset Mgmt. v. Ocwen Fin. Corp.,<i> <\/i>No. 01-cv-01644-REB-CBS, 2010 WL 502721 (D. Colo. Feb. 8, 2010) (rejecting claim that ESI was inaccessible due to burdensomeness after respondents failed to provide specific information regarding their storage practices, the number of storage systems that they would need to search, and their capability to retrieve information from those systems).<\/p>\n<\/div>\n<div>\n<p>[63] <i>What is<\/i> <i>ETL (Extract, Transform, and Reload)?<\/i>, Webopedia, http:\/\/www.webopedia.com\/TERM\/E\/ETL.html (last visited Mar. 12, 2013).<\/p>\n<\/div>\n<div>\n<p>[64] <i>See<\/i> <i>Sedona Principles<\/i>, <i>supra <\/i>note 6, at 30.<\/p>\n<\/div>\n<div>\n<p>[65] <i>Id.<\/i> at 38.<\/p>\n<\/div>\n<div>\n<p>[66] <i>Sedona Database Principles<\/i>, <i>supra <\/i>note 5, at 26.<\/p>\n<\/div>\n<div>\n<p>[67] <i>Id.<\/i> at 31.<\/p>\n<\/div>\n<div>\n<p>[68] Legacy and retired systems are commonly found in corporate acquisitions, where an acquired company\u2019s IT systems tend to be, at best only partially migrated over to the acquiring company or simply taken offline.\u00a0 There may be no current users or administrators of such systems at the current company.\u00a0 <i>See<\/i> <i>id.<\/i> at 14; Herman, <i>supra<\/i> note 46 (\u201cSome systems, especially those that are older, may have been grouped together as a result of certain corporate mergers and acquisitions and may not be operating efficiently or may not be stable . . . .\u201d).<\/p>\n<\/div>\n<div>\n<p>[69] <i>See<\/i> <i>Sedona Database Principles<\/i>, <i>supra <\/i>note 5, at 13.<\/p>\n<\/div>\n<div>\n<p>[70] <i>See<\/i> <i>id.<\/i> at 12.<\/p>\n<\/div>\n<div>\n<p>[71] <i>See<\/i> <i>Sedona Glossary<\/i>, <i>supra<\/i> note 1, at 13.<\/p>\n<\/div>\n<div>\n<p>[72] <i>See<\/i> <i>Data dictionary<\/i>,<i> <\/i>Dictonary.com, http:\/\/www.dictionary.reference.com\/browse\/data+dictionary (last visited Mar. 16, 2013).<\/p>\n<\/div>\n<div>\n<p>[73] <i>Sedona Database Principles<\/i>, <i>supra<\/i> note 5, at 23.<\/p>\n<\/div>\n<div>\n<p>[74] <i>Id.<\/i> at 25.<\/p>\n<\/div>\n<div>\n<p>[75] <i>See, e.g.<\/i>,<i> <\/i>Procter &amp; Gamble Co. v. Haugen, 427 F.3d 727, 739 (10th Cir. 2005) (finding that the responding party would have to purchase a mainframe computer to download and archive the data at its own facilities or purchase the archival data from the third-party at a great cost).<\/p>\n<\/div>\n<div>\n<p>[76] <i>Judicial Conference Report<\/i>, <i>supra<\/i> note 55, at C-83.<\/p>\n<\/div>\n<div>\n<p>[77] However, even if portions of the data from such overwriting systems have disappeared by the time respondent acts, the court may still require production of what remains.\u00a0 <i>See, e.g.<\/i>,<i> <\/i>Burkybile v. Mitsubishi Motors Corp., No. 04 C 4932, 2006 WL 3191541, at *4 (N.D. Ill. Oct. 17, 2006).<\/p>\n<\/div>\n<div>\n<p>[78] <i>Sedona Principles<\/i>, <i>supra<\/i> note 6, at 28.<\/p>\n<\/div>\n<div>\n<p>[79] <i>See supra <\/i>Part IV.<\/p>\n<\/div>\n<div>\n<p>[80] <i>See, e.g.<\/i>, <i>Conditions of Use<\/i>, Sorenson Molecular Genealogy Foundation, http:\/\/www.smgf.org\/terms\/jspx (last visited Mar. 11, 2013); <i>Copyright Information<\/i>, HyperGeertz, http:\/\/hypergeertz.jku.at\/Geertzcopyrightinformation.htm (last visited March 11, 2013); <i>Terms of Use<\/i>, massinvestor, http:\/\/www.massinvestordatabase.com\/terms.php (last visited Mar. 11, 2013).<\/p>\n<\/div>\n<div>\n<p>[81] <i>See infra <\/i>Part VI.D.<\/p>\n<\/div>\n<div>\n<p>[82] For these reasons, the <i>Sedona Database Principles<\/i> actively discourage the use of backup tapes as a methodology.\u00a0 <i>See<\/i> <i>Sedona Database Principles<\/i>, <i>supra <\/i>note 5, at 11.<\/p>\n<\/div>\n<div>\n<p>[83] Dave Russell, <i>The Broken State of Backup<\/i>, Gartner, 1, 5-6, http:\/\/www.cornerstonetelephone.com\/sites\/default\/files\/resources\/Gartner_-_The_Broken_State_of_Backup_(6-09).pdf (last visited Mar. 23, 2013).<\/p>\n<\/div>\n<div>\n<p>[<br \/>\n84] <i>See<\/i> <i>Sedona Database Principles<\/i>, s<i>upra <\/i>note 5, at 20.<\/p>\n<\/div>\n<div>\n<p>[85] <i>See<\/i> <i>id. <\/i>at 31.<\/p>\n<\/div>\n<div>\n<p>[86] <i>Id.<\/i> at 26.<\/p>\n<\/div>\n<div>\n<p>[87] <i>Id. <\/i>at 19.<\/p>\n<\/div>\n<div>\n<p>[88] <i>See, e.g.<\/i>,<i> <\/i>Margel v. E.G.L. Gem Lab Ltd.,<i> <\/i>No. 04 Civ. 1514(PAC)(HBP), 2008 WL 2224288, at *4-6 (S.D.N.Y. May 29, 2008) (ordering respondent to produce the database as well as the reports from the database because the database was not in the same form, under FRCP 34, as the reports).\u00a0 <i>But see, e.g.<\/i>, EEOC<i> <\/i>v. Supervalu, Inc.<i>,<\/i> No. 09 CV 5637, 2010 WL 5071196, at *8 (N.D. Ill. Dec. 7, 2010) (rejecting a request that would have required creation of custom report that would have taken two weeks work where requestor could not prove that the relevancy of the data to be obtained was greater than the burden on the respondent).<\/p>\n<\/div>\n<div>\n<p>[89] <i>See, e.g.<\/i>,<i> <\/i>Soto v. Genentech, Inc., No. 08-60331-CIV, 2008 WL 4621832, at *12 (S.D. Fla. Oct. 17, 2008) (allowing responding party to produce detailed log of data contents in lieu of creation of custom reports that would have required approximately 64 hours of work);<i> see also <\/i>Getty Props. Corp. v. Raceway Petroleum, Inc.,<i> <\/i>No. Civ. A. 99-CV-4395DMC, 2005 WL 1412134, at *4 (D.N.J. June 14, 2005).<\/p>\n<\/div>\n<div>\n<p>[90] This method was originally suggested by Thomas Allman in an early and seminal review of the then brand-new 2006 ESI FRCP Amendments.\u00a0 <i>See<\/i> Thomas Y. Allman, <i>Managing Preservation Obligations After The 2006 Federal E-Discovery Amendments<\/i>, 13 Rich. J.L. &amp; Tech.. 9, 48 (2007), <i>available at<\/i> http:\/\/law.richmond.edu\/jolt\/v13i3\/article9.pdf.<\/p>\n<\/div>\n<div>\n<p>[91] <i>See, e.g.<\/i>,<i> In re <\/i>Ford Motor Co.,<i> <\/i>345 F.3d 1315, 1316-17 (11th Cir. 2003); <i>In re <\/i>Lowe&#8217;s Cos., Inc., 134 S.W.3d 876, 879-80 (Tex. App. 2004).<\/p>\n<\/div>\n<div>\n<p>[92] Fed. R. Civ. P. 34(a) advisory committee\u2019s note.<\/p>\n<\/div>\n<div>\n<p>[93] <i>Sedona Database Principles<\/i>, s<i>upra <\/i>note 5, at 16.<\/p>\n<\/div>\n<div>\n<p>[94] <i>Id<\/i>. at 17.<\/p>\n<\/div>\n<div>\n<p>[95] <i>See id. <\/i>at 3.<\/p>\n<\/div>\n<div>\n<p>[96] <i>Id. <\/i>at 10.<\/p>\n<\/div>\n<div>\n<p>[97] <i>Id.<\/i> at 36.<\/p>\n<\/div>\n<div>\n<p>[98] <i>Sedona Database Principles<\/i>, s<i>upra <\/i>note 5, at 36.<\/p>\n<\/div>\n<div>\n<p>[99] Fed. R. Civ. P. 34(b)(2)(E).<\/p>\n<\/div>\n<div>\n<p>[100] <i>See, e.g.<\/i>, Powerhouse Marks, L.L.C. v. Chi Hsin Impex, Inc<i>.,<\/i> No. Civ.A.04CV73923DT, 2006 WL 83477 (E.D. Mich. Jan. 12, 2006) (showing that the defendant produced financial database by delivering 1,771 Bates stamped pages of print outs of the raw field data).<\/p>\n<\/div>\n<div>\n<p>[101] <i>See, e.g.<\/i>,<i> In re <\/i>eBay Seller Antitrust Litig., No. C 07\u20131882 JF, 2009 WL 2524502, at *2 (N.D. Cal. Aug. 17, 2009) (ordering eBay to create a new data set to produce additional responsive documents, despite its Senior Director of Data Warehouse Development\u2019s representation that \u201cit would take an engineer forty-eight hours to format a query, at a cost of $7,200\u201d in order to do so).<\/p>\n<\/div>\n<div>\n<p>[102] <i>See Sedona Database Principles<\/i>, s<i>upra <\/i>note 5, at 37.<\/p>\n<\/div>\n<div>\n<p>[103] <i>Sedona Principles<\/i>, s<i>upra <\/i>note 6, at 60.<\/p>\n<\/div>\n<div>\n<p>[104] <i>See, e.g.<\/i>,<i> In re <\/i>Netbank Sec. Litig., 259 F.R.D. 656, 681-82, 683 (N.D. Ga. 2009);<i> <\/i>Hagenbuch v. 3B6 Sistemi Elettronici Industriali S.R.L., No. 04 C 3109, 2006 WL 665005, at *3-4 (N.D. Ill. Mar. 8, 2006).<\/p>\n<\/div>\n<div>\n<p>[105] <i>See, e.g.<\/i>,<i> <\/i>Camesi v. Univ. Pittsburgh Med. Ctr., No. 09\u201385J, 2010 WL 2104639, at *7 (W.D. Pa. May 24, 2010); <i>see also, e.g.<\/i>, Chevron Corp. v. Stratus Consulting, Inc., No. 10\u2013cv\u201300047-MSK-MEH, 2010 WL 3489922, at *2-4 (D. Colo. Aug. 31, 2010).<\/p>\n<\/div>\n<div>\n<p>[106] <i>See, e.g.<\/i>,<i> <\/i>Ojeda-Sanchez v. Bland Farms, LLC, No. CV608-096, 2009 WL 2365976, at *3 (S.D. Ga. July 31, 2009);<i> <\/i>Perez-Farias v. Global Horizons, Inc., No. CV-05-3061-MWL, 2007 WL 991747, at *3 (E.D. Wash. Mar. 30, 2007).<\/p>\n<\/div>\n<div>\n<p>[107] Michael Spencer &amp; Diana Fasching, <i>Less Production Can be More in Database Discovery<\/i>, L. Tech. News, Oct. 26, 2012.<\/p>\n<\/div>\n<div>\n<p>[108] Even highly sophisticated corporations have at times experienced disastrous failures in attempting to install and use high-end database systems.\u00a0 <i>See<\/i> Ericka Chickowski, <i>Five ERP Disasters Explained<\/i>, Baseline Mag., Apr. 4, 2009, <i>available at <\/i>http:\/\/www.baselinemag.com\/c\/a\/ERP\/Five-ERP-Disasters-Explained-878312\/.<\/p>\n<\/div>\n<div>\n<p>[109] <i>See Sedona Principles<\/i>, <i>supra<\/i> note 6, at 5.<\/p>\n<\/div>\n<div>\n<p>[110] <i>See<\/i> <i>id.<\/i> at 7.<\/p>\n<\/div>\n<div>\n<p>[111] <i>See<\/i> Tomlinson v. El Paso Corp., 245 F.R.D. 474, 477 (D. Colo. 2007) (requiring a party to turn over data from third-party database of ERISA information because ERISA created clear duties for the employer that negated any claim that such third party data could not be within its possession, custody or control).<\/p>\n<\/div>\n<div>\n<p>[112] <i>See <\/i>Alberto G. Araiza, <i>Electronic Discovery in the Cloud<\/i>, 2011 Duke L. &amp; Tech. Rev. 8, 33 (2011).<\/p>\n<\/div>\n<div>\n<p>[113] <i>Sedona Database Principles<\/i>, <i>supra<\/i> note 5, at 34.<\/p>\n<\/div>\n<div>\n<p>[114] <i>See <\/i>Lorraine v. Markel Am. Ins. Co., 241 F.R.D. 534, 538 (D. Md. 2007).<\/p>\n<\/div>\n<div>\n<p>[115] <i>Sedona Database Principles<\/i>, <i>supra<\/i> note 5, at 32.<\/p>\n<\/div>\n<div>\n<p>[116] <i>See, e.g<\/i>., <i>In re <\/i>Vee Vinhee, 336 B.R. 437, 447-49 (B.A.P. 9th Cir. 2005).<\/p>\n<\/div>\n<div>\n<p>[117] <i>Id.<\/i> at 448-49.<\/p>\n<\/div>\n<div>\n<p>[118] <i>Id.<\/i> at 448.<\/p>\n<\/div>\n<div>\n<p>[119] <i>Compare<\/i> R.I. Managed Eye Care, Inc. v. Blue Cross &amp; Blue Shield of R.I.,<i> <\/i>996 A.2d 684, 691 (R.I. 2010) (reiterating a four part test for determining the admissibility of business records under the hearsay rule), <i>with<\/i> <i>In re Vee Vinhee<\/i>, 336 B.R. at 446 (defining an eleven part test for determining the admissibility of electronic records under the hearsay rule).<\/p>\n<\/div>\n<div>\n<p>[120] <i>See Sedona Database Principles<\/i>, <i>supra<\/i> note 5, at 8-9.<\/p>\n<\/div>\n<div>\n<p>[121] <i>See generally<\/i> Council Directive 90\/46\/EC, 1995 O.J. (L 281) 39-45 (defining specific privacy protections to be afforded to personal information).<\/p>\n<\/div>\n<div>\n<p>[122] <i>See, e.g.<\/i>, U.S. Dept. of Commerce, <i>Safe Harbor Privacy Principles<\/i>, export.gov (July 21, 2000), http:\/\/export.gov\/safeharbor\/eu\/eg_main_018475.asp (defining protections for U.S. citizens\u2019 data exported to the European Union); <i>see also<\/i> Commission Decision 2000\/520\/EC, 2000 O.J. (L 215) 7-9 (accepting U.S. Safe Harbor Privacy Principles).<\/p>\n<\/div>\n<div>\n<p>[123] <i>See, e.g.<\/i>, Datenschutzgesetz 2000 [DSG 2000] Bundesgesetzblatt [BGBl] No. 165\/1999, \u00a7\u00a7 51-52 (Austria) (imposing up to a year in prison and 25,000 Euro fine per violation).<\/p>\n<\/div>\n<div>\n<p>[124] <i>Sedona Database Principles<\/i>, <i>supra<\/i> note 5, 21-38.<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Download PDF Cite as: Conrad Jacoby, Jim Vint &amp; Michael Simon, Databases Lie!\u00a0Successfully Managing Structured Data, The Oft-Overlooked ESI, 19\u00a0RICH. J.L. &amp; TECH 9 (2013), available at\u00a0http:\/\/jolt.richmond.edu\/v19i3\/article9.pdf. &nbsp; By Conrad Jacoby,* Jim Vint,** &amp; Michael Simon*** &nbsp; [1]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Legal professionals regularly advise clients to ensure that the storage, retention, and accessibility of their Electronically-Stored Information [&hellip;]<\/p>\n","protected":false},"author":4287,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[1228],"tags":[],"class_list":["post-1240","post","type-post","status-publish","format-standard","hentry","category-articles"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-k0","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/1240","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/4287"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=1240"}],"version-history":[{"count":0,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/1240\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=1240"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=1240"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=1240"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}