{"id":2678,"date":"2015-03-20T17:41:35","date_gmt":"2015-03-20T17:41:35","guid":{"rendered":"http:\/\/jolt.richmond.edu\/?p=2678"},"modified":"2019-03-08T19:52:23","modified_gmt":"2019-03-09T00:52:23","slug":"the-big-data-collection-problem-of-little-mobile-devices","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2015\/03\/20\/the-big-data-collection-problem-of-little-mobile-devices\/","title":{"rendered":"The Big Data Collection Problem of Little Mobile Devices"},"content":{"rendered":"<p><a href=\"http:\/\/jolt.richmond.edu\/v21i3\/article10.pdf\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-128\" src=\"http:\/\/jolt.richmond.edu\/files\/2012\/05\/pdf_icon1.gif\" alt=\"pdf_icon\" width=\"16\" height=\"16\" \/>DownloadPDF<\/a><\/p>\n<p style=\"text-align: center\">Cite as: Michael Arnold &amp; Dennis R. Kiker, The Big Data Collection Problem of Little Mobile Devices, 21 Rich. J.L. &amp; Tech. 10 (2015), http:\/\/jolt.richmond.edu\/v21i3\/article10.pdf.<\/p>\n<p style=\"text-align: center\">by Michael Arnold* &amp; Dennis R. Kiker**<\/p>\n<p>[1]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 There should be little question that mobile device-based data are discoverable if relevant.\u00a0 However, as was the case with ordinary computer-based data a decade or more ago, there is a tendency to believe that there is only one way to collect such data\u2014\u201cforensically.\u201d[1]\u00a0 This article will demonstrate that there are a number of potentially reasonable ways to collect mobile device data, and that the choice depends, as it does for any other type of information, on the facts and circumstances of the case.\u00a0 We will first examine the proliferation and impact of mobile data.\u00a0 Then, we will survey the case law demonstrating both that mobile data are relevant and that the principle of reasonableness applies to mobile data as it does to any other source.\u00a0 Next, we will outline the various methods for collecting mobile data, any of which might be reasonable under given circumstances.\u00a0 Finally, we will consider other complicating factors that will impact the decision about what type of collection is appropriate under the circumstances of a give case.<\/p>\n<p><strong>I.\u00a0 Prevalence and Relevance of Mobile Data<\/strong><\/p>\n<p>[2]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 It goes without saying that mobile devices are ubiquitous.\u00a0 Research by the Pew Research Center shows that:<\/p>\n<p style=\"padding-left: 30px\">\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 90% of American adults have a cell phone<\/p>\n<p style=\"padding-left: 30px\">\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 58% of American adults have a smartphone<\/p>\n<p style=\"padding-left: 30px\">\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 32% of American adults own an e-reader<\/p>\n<p style=\"padding-left: 30px\">\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 42% of American adults own a tablet computer[2]<\/p>\n<p>[3]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 These data represent a 37% increase in cell phone ownership since 2000, and a 23% increase in smartphone ownership in less than three years.[3]<\/p>\n<p>[4]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The proliferation of mobile devices is not limited to personal use and does not only affect individuals.\u00a0 Indeed, business use of mobile devices is more complex due to the trend towards \u201cbring your own device\u201d (\u201cBYOD\u201d) policies, which either allow or require employees to provide their own mobile devices for work use.[4]\u00a0 The obvious result is that employees\u2019 mobile devices will contain a larger mix of personal and business data, with the corollary result that companies will have to produce more information from a wider variety of mobile devices.[5]\u00a0 In a survey conducted by Norton Rose Fulbright, 41% of the responding companies had to preserve or collect data from employees\u2019 mobile devices in support of litigation or investigations, an increase of more than 10% in two years.[6]\u00a0 Indeed, in a recent survey by BDO Consulting, \u201cthe largest percentage of in-house counsel (22.5 percent) say managing mobile and social networking data is the number one issue they will face in the near future[.]\u201d[7]\u00a0 Not surprisingly, then, mobile devices are becoming increasingly important sources of potentially relevant information.<\/p>\n<p>[5]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 There was, perhaps, a time when attorneys could legitimately overlook data on mobile devices in some cases.\u00a0 When Blackberry devices dominated the market, and were generally synched to enterprise servers, there was little reason to believe that potentially relevant data existed on the mobile device that was not available from a more accessible source.[8]\u00a0 That has changed.\u00a0 First, there is a wide variety of information on mobile devices that is likely not available anywhere else.\u00a0 Types of data available on a smartphone or tablet include:<\/p>\n<p style=\"padding-left: 30px\">\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 E-mail<\/p>\n<p style=\"padding-left: 30px\">\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 Text messages<\/p>\n<p style=\"padding-left: 30px\">\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 Voicemail messages<\/p>\n<p style=\"padding-left: 30px\">\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 User information stored as mini-databases or structured text files (e.g., address books, call history, favorite telephone numbers, browser history, bookmarks, recent Internet searches, cookies)<\/p>\n<p style=\"padding-left: 30px\">\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 Photographs<\/p>\n<p style=\"padding-left: 30px\">\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 Video recordings<\/p>\n<p style=\"padding-left: 30px\">\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 Voice recordings<\/p>\n<p style=\"padding-left: 30px\">\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 Notes<\/p>\n<p style=\"padding-left: 30px\">\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 GPS data (which may be attached to other files, such as photographs)<\/p>\n<p style=\"padding-left: 30px\">\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 Maps and navigation history<\/p>\n<p style=\"padding-left: 30px\">\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 Wi-fi and cellular location history[9]<\/p>\n<p>[6]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Second, the data on a mobile device may be quite relevant even in routine litigation.\u00a0 Consider just two common scenarios, starting with routine vehicle accidents.\u00a0 The National Highway Traffic Safety Administration (NHTSA) reports that in 2012 alone, 3,328 people were killed and approximately 421,000 people were injured in accidents involving distracted driving.[10]\u00a0 Current research confirms that the risk of accidents increases significantly with the use of mobile devices while driving.[11]\u00a0 Further, an estimated 9% of all drivers do so while using a cell phone or sending and receiving text messages.[12]\u00a0 Driver conduct is an issue in just about every automobile accident case, and mobile devices are increasingly becoming a key source of evidence on that issue.[13]<\/p>\n<p>[7]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 On the business side of litigation, mobile devices are no less important.\u00a0 Some estimates indicate that there has been a 43% increase in the use of instant messaging through mobile devices as a way employees conduct business.[14]\u00a0 Unlike e-mail and voicemail, text messages are generally not duplicative of data that can be found on the company\u2019s network.[15]\u00a0 Whether the case involves allegations of employment discrimination or product liability, individual employees implicated in the litigation are increasingly likely to have potentially relevant information on mobile devices that can be found nowhere else.<\/p>\n<p style=\"padding-left: 30px\"><strong>A.\u00a0 Emerging Case Law Involving Mobile Data<\/strong><\/p>\n<p>[8]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 A number of recent cases have directly addressed mobile data, typically in the context of spoliation.\u00a0 For example, Calderon v. Corporacion Puertorrique a de Salud was a sexual harassment case in which the plaintiff selectively retained messages on his cell phone.[16]\u00a0 Records from the plaintiff\u2019s mobile service provider indicated that plaintiff failed to produce more than thirty-eight text messages sent from the account of the alleged harasser.[17] \u00a0The court held that the plaintiff\u2019s \u201cdecision not to forward or save the unproduced texts and photos from prpng@hotmail.com constitutes \u2018conscious abandonment of potentially useful evidence\u2019 that indicates that he believed those records would not help his side of the case.\u201d[18]\u00a0 The court determined that plaintiff\u2019s failure to preserve the text messages \u201cseverely prejudice[d]\u201d the defendants, requiring an adverse inference instruction at trial.[19]<\/p>\n<p>[9]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 In re Pradaxa (Dabigatran Etexilate) Products Liability Litigation concerned a nationwide multi-district litigation (MDL) in which the plaintiffs moved for sanctions for spoliation of, among other things, business-related text messages.[20]\u00a0 After noting that the duty to preserve for each of the two defendants arose in February and April, 2012, respectively, the court went on to severely chastise the defendants for failing to institute a legal hold specifically identifying text messaging until October, 2013, even though the plaintiffs had specifically requested text messages in its initial discovery requests, and the defendants\u2019 own documents showed that they \u201cdirected their sales force to use texts to communicate with their supervisors, district managers, and others.\u201d[21]\u00a0 In fact, despite that \u201c[i]t is certainly common knowledge that texting has become the preferred means of communication,\u201d the defendants failed to suspend the auto-deletion of text messages on company issued and programmed cell phones.[22]\u00a0 The court ordered the immediate production of any relevant text messages, reserving the right to impose sanctions if the data were not available.[23]<\/p>\n<p>[10]\u00a0\u00a0\u00a0\u00a0 Lastly, EEOC v. Original Honeybaked Ham Co. of Georgia involved the defendant\u2019s motion to compel a wide variety of information from the class representatives in this sexual harassment, hostile environment and retaliation case.[24]\u00a0 Based on information discovered on one class representative\u2019s Facebook page, the defendant sought production of social media content, text messages, e-mail and other electronically stored information relevant to the plaintiffs\u2019 alleged damages, as well as their credibility and bias.[25]\u00a0 The court first found that the types of information sought were no different than any other discoverable information:<\/p>\n<p style=\"padding-left: 30px\">As a general matter, I view this content logically as though each class member had a file folder titled \u201cEverything About Me,\u201d which they have voluntarily shared with others. \u00a0If there are documents in this folder that contain information that is relevant or may lead to the discovery of admissible evidence relating to this lawsuit, the presumption is that it should be produced. \u00a0The fact that it exists in cyberspace on an electronic device is a logistical and, perhaps, financial problem, but not a circumstance that removes the information from accessibility by a party opponent in litigation.[26]<\/p>\n<p>After determining that the requested information was, in fact, potentially relevant, the court ordered its production.[27]\u00a0 To protect the individual plaintiffs\u2019 privacy interests, the court appointed a special master to retrieve all of the data, including text messages on the plaintiffs\u2019 cell phones, and submit information believed to be relevant for in camera inspection.[28]<\/p>\n<p style=\"padding-left: 30px\"><strong>B.\u00a0 Case Law Regarding Collection Methods<\/strong><\/p>\n<p>[11]\u00a0\u00a0\u00a0\u00a0 As demonstrated above, data on mobile devices will often be relevant and, therefore, subject to preservation and possibly collection.\u00a0 The legal standards applicable to the method chosen to collect that data, however, are no different than the standards applicable to any other relevant information: \u201cWhether preservation or discovery conduct is acceptable in a case depends on what is reasonable, and that in turn depends on whether what was done\u2014or not done\u2014was proportional to that case and consistent with clearly established applicable standards.\u201d[29]\u00a0 The determination of whether discovery conduct was reasonable or not, \u201cdepends heavily on the facts and circumstances of each case and cannot be reduced to a generalized checklist of what is acceptable or unacceptable.\u201d[30]<\/p>\n<p>[12]\u00a0\u00a0\u00a0\u00a0 In Nola Spice Designs, LLC v. Haydel Enterprises, the court addressed the propriety and necessity of forensic images.[31]\u00a0 In that trademark infringement case, the plaintiff sought an order compelling the defendants to, among other things, \u201csubmit their computers to an exhaustive forensic examination . . .\u201d[32]\u00a0 The court rejected the plaintiff\u2019s request because it \u201cfar exceed[ed] the proportionality limits imposed by Fed. R. Civ. P. 26(b)(2)(C)\u2014expressly made applicable to ESI by Rule 26(b)(2)(B) . . .\u201d[33]\u00a0 The court explained:<\/p>\n<p style=\"padding-left: 30px\">[Plaintiff\u2019s] request for an exhaustive forensic examination of [defendants\u2019] computers is within the scope of ESI discovery contemplated by Fed. R. Civ. P. 34(a)(1)(A).\u00a0 At the same time, however, such requests are also subject to the proportionality limitations applicable to all discovery under Rule 26(b)(2)(C), including the prohibition of discovery that is unreasonably cumulative or duplicative or that could be obtained from some more convenient, less burdensome or less expensive source, or the benefit of which is outweighed by its burden or expense, when considering the needs of the case, the amount in controversy, the parties\u2019 resources, the importance of the issues at stake and the importance of the proposed discovery to those issues.\u00a0 Certainly, the Official Advisory Committee Notes to the 2006 Amendments to Rule 34 relating to electronic discovery of the type sought by Haydel counsel caution:<\/p>\n<p>\u201cAs with any other form of discovery, issues of burden and intrusiveness raised by requests to test . . . can be addressed under Rules 26(b)(2) and 26(c).\u00a0 Inspection or testing of certain types of electronically stored information or of a responding party\u2019s electronic information system may raise issues of confidentiality or privacy.\u00a0 The addition of testing and sampling to Rule 34(a) with regard to . . . electronically stored information is not meant to create a routine right of direct access to a party\u2019s electronic information system, although such access might be justified in some circumstances.\u00a0 Courts should guard against undue intrusiveness resulting from inspecting or testing such systems.\u201d[34]<\/p>\n<p>[13]\u00a0\u00a0\u00a0\u00a0 Indeed, although<\/p>\n<p style=\"padding-left: 30px\">[F]orensic computer examinations of the type sought by [plaintiff] in this motion are \u2018not uncommon in the course of civil discovery, . . . \u201c[c]ourts have been cautious in requiring the mirror imaging of computers where the request is extremely broad in nature and the connection between the computers and the claims in the lawsuit are unduly vague or unsubstantiated in nature.\u201d[35]<\/p>\n<p>Courts have only granted motions to compel forensic examinations where \u201cwhere the moving party has demonstrated that its opponent has defaulted in its discovery obligations by unwillingness or failure to produce relevant information by more conventional means.\u201d[36]<\/p>\n<p>[14]\u00a0\u00a0\u00a0\u00a0 The Sixth Circuit Court of Appeals reached a similar conclusion in John B. v. Goetz.[37] \u00a0This class action litigation spanning over 10 years involved implementation of the TennCare program in Tennessee.[38]\u00a0 During the course of the litigation, disputes arose about the scope of the defendants\u2019 preservation and production of ESI.[39]\u00a0 Following a series of hearing on motions to compel and reconsider, the district court entered an order allowing \u201cplaintiffs\u2019 computer expert to make forensic copies of the hard drives of identified computers, including not only those at the work stations of the state\u2019s key custodians, but also any privately owned computers on which the custodians may have performed or received work relating to the TennCare program.\u201d[40]\u00a0 The defendants filed a motion for an emergency stay and a petition for mandamus, both of which the appellate court granted, finding that the district court\u2019s order constituted an abuse of discretion.[41]\u00a0 The court first acknowledged that a \u201cparty may choose on its own to preserve information through forensic imaging, and district courts have, for various reasons, compelled the forensic imaging and production of opposing parties&#8217; computers.\u201d[42]\u00a0 One the other hand, the court cautioned that:<\/p>\n<p style=\"padding-left: 30px\">Civil litigation should not be approached as if information systems were crime scenes that justify forensic investigation at every opportunity to identify and preserve every detail. . . .\u00a0 [M]aking forensic image backups of computers is only the first step of an expensive, complex, and difficult process of data analysis that can divert litigation into side issues and satellite disputes involving the interpretation of potentially ambiguous forensic evidence.[43]<\/p>\n<p>The court found insufficient evidence in the record to suggest that the defendants intentionally deleted relevant information or were unwilling or unable to preserve and produce such information in the future.[44]\u00a0 For this reason, and because the ordered forensic imaging implicated \u201csignificant privacy and confidentiality concerns,\u201d the court granted the defendants\u2019 petition and overturned the district court\u2019s orders.[45]<\/p>\n<p>[15]\u00a0\u00a0\u00a0\u00a0 Lee v. Stonebridge Life Ins. Co. involved a request for a forensic image of the plaintiff\u2019s personal computer and iPhone.[46]\u00a0 Lee was a class action lawsuit alleging that the defendant insurance company sent unauthorized text messages to prospective purchasers of its insurance products.[47] \u00a0During discovery, the defendants sought production of the named plaintiff\u2019s personal computer and iPhone for the purpose of capturing a forensic image of each in an attempt to recover copies of any relevant text messages.[48]\u00a0 The court denied the defendants\u2019 motion.[49] \u00a0As in Goetz, the court first acknowledged that Rule 34 permits parties to seek inspection and testing of \u201cdata or data compilations . . . stored in any medium.\u201d[50]\u00a0 Nevertheless, the court held that the defendants \u201cfailed to demonstrate sufficient good cause to warrant the extreme step of allowing it to conduct a forensic inspection of Plaintiff\u2019s iPhone and personal computer.\u201d[51]\u00a0 The court noted that a backup of the iPhone at issue was available on the plaintiff\u2019s personal computer, that the plaintiff had already agreed to search for and produce any relevant information stored on her personal computer, and emphasized that there was no evidence of wrongdoing by the plaintiff: \u201cabsent a showing of misconduct on Plaintiff\u2019s part such that serious questions exist as to the reliability and the completeness of Plaintiff\u2019s expert\u2019s search, [the defendant] is not entitled to a forensic examination of Plaintiff\u2019s personal computer.\u201d[52]<\/p>\n<p>[16]\u00a0\u00a0\u00a0\u00a0 In contrast, Olney v. Job.Com is a good example of a case in which forensic images were critical to the court\u2019s decision.[53]\u00a0 Olney was a class action alleging that the defendants made unsolicited calls to the named plaintiff\u2019s cell phone in violation of the Telephone Consumer Protection Act.[54]\u00a0 The defendants requested access to the cell phone and computer the plaintiff alleged were involved in the communications between the plaintiff and the defendants, and the court ultimately ordered the plaintiff to deliver both to a neutral expert for imaging.[55]\u00a0 In a very detailed opinion, the court reviewed the analyses by competing experts of the plaintiff\u2019s personal computer to determine whether the plaintiff had deleted relevant information, either intentionally or negligently.[56]\u00a0 The court ultimately determined that the plaintiff had in fact engaged in conduct that was, at various points in the litigation, negligent, grossly negligent, and willful, justifying an adverse inference instruction and monetary sanctions.[57]<\/p>\n<p>[17]\u00a0\u00a0\u00a0\u00a0 The Olney opinion is instructive for a number of reasons.\u00a0 First, it involves a situation that exemplifies the need for forensic imaging and analysis: where there are allegations that specific information has been deleted.\u00a0 Second, it illustrates the complexity and potentially high cost of forensic analysis.\u00a0 Here, the parties agreed on a neutral expert to image and analyze the data from the plaintiffs\u2019 computer.[58]\u00a0 Apparently unsatisfied with the results of that analysis, each of the parties then obtained permission to retain their own experts to perform independent analyses.[59]\u00a0 These experts proceeded to generate reports, supplemental reports, rebuttal reports, and supplemental declarations, to the point where the court finally declined to consider the last submissions, as \u201c[r]ebuttal expert reports [would be] potentially endless in this circumstance[.]\u201d[60]\u00a0 Finally, the court notes that the plaintiff \u201cretained experienced class-action counsel with three law firms who should have known his computer could contain potentially relevant information,\u201d leaving the plaintiff with little excuse for not preserving data on his computer.[61]\u00a0 This underscores the fact that adequate preservation steps will typically obviate the need for forensic collection and analysis.<\/p>\n<p>[18]\u00a0\u00a0\u00a0\u00a0 Finally, Ackerman v. PNC Bank demonstrates that sometimes the simplest collection method is adequate to the needs of the case .[62] \u00a0In her appeal from the magistrate judge\u2019s order denying her motion to compel discovery and for sanctions, the plaintiff alleged that the defendants had \u201cinadequately gathered electronically stored information (\u2018ESI\u2019) or unlawfully destroyed ESI,\u201d and \u201cviolated Fed. R. Civ. P. 34(b)(2)(E) by producing hard copy ESI documents without the underlying metadata.\u201d[63]\u00a0 The court disagreed, noting on the latter point that:<\/p>\n<p style=\"padding-left: 30px\">Rule 34(b)(2)(E) does not specifically reference the production of metadata, but refers to a party\u2019s obligation to produce documents as they are kept \u201cin the usual course of business\u201d or organized and labeled according to corresponding discovery request categories.\u00a0 If the discovery request does not specify the form for producing ESI, Rule 34 requires a party to produce it in the form \u201cin which it is ordinarily maintained or in a reasonably usable form or forms.\u201d[64]<\/p>\n<p>It is readily apparent that the case law does not require a specific collection method or form of production for any type of information, including mobile data.\u00a0 Rather, the collection method should be reasonable and appropriate for the circumstances of the case.<\/p>\n<p><strong>II.\u00a0 Defensible Mobile Data Collection Options<\/strong><\/p>\n<p>[19]\u00a0\u00a0\u00a0\u00a0 Having made the determination that information contained on mobile devices is potentially relevant, attorneys must then determine whether to collect the data, and if so, how.\u00a0 In making these decisions, there are many factors to consider, including the complexity and cost of the collection relative to the issues at stake in the litigation.\u00a0 Here, we will first survey the available collection methods and discuss the circumstances under which each might be appropriate.\u00a0 Later in this article, we will also discuss some of the challenges and complicating factors associated with mobile data collection.<\/p>\n<p style=\"padding-left: 30px\"><strong>A.\u00a0 No Collection<\/strong><\/p>\n<p>[20]\u00a0\u00a0\u00a0\u00a0 Sometimes, not collecting mobile data is a perfectly reasonable option.\u00a0 For example, if the only data that are potentially relevant to the matter are e-mails, and the company has implemented an insulating technology to secure communications on the mobile device and ensure that all business-related e-mails are synchronized with the enterprise e-mail server, then collecting from the mobile device would yield only duplicate data.[65]<\/p>\n<p>[21]\u00a0\u00a0\u00a0\u00a0 Occasionally, all that is needed with respect to mobile data are call and text logs, and in most cases this information can be obtained via provider bills or specific detail requests that do not require the device itself.[66]\u00a0 While the content of text messages is not shown on bills or generally available without collection from the device, these types of call and text logs are not easily erased by an owner or user and benefit from having an impartial timestamp for time sensitive events such as might be required in a distracted driving case.[67] \u00a0Cellular providers can also provide cellular tower triangulation data that can identify the approximate location of a mobile device at a given time.[68]<\/p>\n<p style=\"padding-left: 30px\"><strong>B.\u00a0 Hard Copy Collection<\/strong><\/p>\n<p>[22]\u00a0\u00a0\u00a0\u00a0 As odd as it might seem, paper may sometimes be a defensible form of collecting mobile data.\u00a0 Most modern mobile devices are equipped with applications that enable wireless printing from the device.[69] \u00a0In some cases, where metadata are not of interest or at issue, the parties may be perfectly satisfied with paper copies of e-mails, text messages, or other content on a mobile device.[70]\u00a0 Simply because it is possible to collect ESI from mobile devices does not mean that it is necessary in every case.<\/p>\n<p style=\"padding-left: 30px\"><strong>C.\u00a0 Mobile Device Collection<\/strong><\/p>\n<p>[23]\u00a0\u00a0\u00a0\u00a0 There are essentially three methods of collecting data from a mobile device: file level collection, logical collection, and physical collection.[71]<\/p>\n<p style=\"padding-left: 60px\"><strong>1.\u00a0 File Level Collection<\/strong><\/p>\n<p>[24]\u00a0\u00a0\u00a0\u00a0 The simplest method of collecting data from a mobile device is to essentially treat it as an external hard drive.\u00a0 File level collections focus on active data that can be readily accessed through the device\u2019s operating system, the operating system of a partner device (such as a connected computer), or via third party software.[72]\u00a0 This is similar in nature to collecting the active files on a computer, which are the files that can be identified using the computer\u2019s operating system, such as Windows.[73]<\/p>\n<p>[25]\u00a0\u00a0\u00a0\u00a0 Depending on the needs of the case, and particularly on the importance of preserving metadata associated with the target files, an active file collection can be accomplished as simply as connecting the device to a partner computer as a USB storage device (external hard drive), and using the computer\u2019s operating system to navigate to the target files and copying them to the computer.[74] \u00a0It is important to note that this method has the highest risk of altering both metadata of the files and the state of the mobile device should a physical image potentially be required in the future.[75]\u00a0 On the other hand, steps can be taken to mitigate any alteration of the files on the device or to the metadata of the files collected.[76]\u00a0 Usually a USB write-blocker can be used to preserve the device, but not all devices will communicate with the collections computer with such a device installed.[77]<\/p>\n<p>[26]\u00a0\u00a0\u00a0\u00a0 Where metadata may be at issue or will be important for other reasons (such as culling and filtering), commercial software such as Access Data\u2019s FTK Imager, Pinpoint Labs Safecopy or Wide Angle\u2019s TouchCopy can be used to ensure that the metadata on both the mobile device and the collection drive are not altered as part of the collection.[78]\u00a0 Manual file copy collections are the most limited in what they can collect, as most devices that are not rooted or jail-broken[79] will limit the accessible areas on the device to maintain application security.[80]<\/p>\n<p>[27]\u00a0\u00a0\u00a0\u00a0 Situations where file level collection might be appropriate include cases where there are no relevant call\/messaging logs, and a user has identified a few select files on their mobile device that may need to be collected.[81]\u00a0 File level collection is far superior to having the user e-mail the file to a person collecting the data, such as an IT person, counsel or in-house legal representative, because the latter method creates yet another copy of the file that should be preserved or collected.[82]\u00a0 Some devices can be plugged directly into a prepared collection system and accessed just like a portable hard drive and the files exposed for collection.[83]<\/p>\n<p style=\"padding-left: 60px\"><strong>2.\u00a0 Forensic Logical Copy<\/strong><\/p>\n<p>[28]\u00a0\u00a0\u00a0\u00a0 A forensic logical copy involves connecting the mobile device to tools or equipment and copying either everything or selected files from the device or any installed memory devices.[84]\u00a0 During a logical collection, certain data such as pictures, music, e-mail, text messages and other files are copied with tools like FTK imager, Cellebrite and others to other media to be processed, evaluated and reviewed.[85]\u00a0 A logical collection does not copy or access anything that is not on the device and does not copy latent information such as slack-space from deleted files or certain protected areas of a phone unless that device has been modified (often referred to as hacked, rooted or jail broken).[86] \u00a0Logical images do not collect unsaved data from volatile memory (e.g. from RAM).[87]<\/p>\n<p>3.\u00a0 Logical Collection of Synchronized Data<\/p>\n<p>[29]\u00a0\u00a0\u00a0\u00a0 When a mobile device is synchronized with another location, it may be reasonable to collect from that location as opposed to the device itself.\u00a0 It will almost certainly be simpler and more cost effective.[88] \u00a0For example, when a mobile device management system (MDM) is implemented within a company, certain applications are installed, or devices are routinely connected to other systems, the devices may be configured to back up their data to one of several locations[89], including:<\/p>\n<p style=\"padding-left: 30px\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The cloud,<\/p>\n<p style=\"padding-left: 30px\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 A dedicated server, application host or file share, or<\/p>\n<p style=\"padding-left: 30px\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 A specific partner computer or device.[90]<\/p>\n<p>[30]\u00a0\u00a0\u00a0\u00a0 Care must be taken to ensure that the synchronized location does not materially change between the identification and the actual collection of that source.[91]\u00a0 One of the safest ways to ensure that a synchronized location does not change is to disable the synchronization feature of the mobile device by turning the device off, setting the device to airplane mode and\/or not connecting the device to any partner computers, sometimes referred to as \u201cdocking.\u201d[92]\u00a0 Synchronized locations may also be affected or accessed by more than one device.\u00a0 For instance, Gmail, Dropbox and Facebook are common examples of locations that may be connected to more than one device or be changed from a remote computer even after the intended device has been secured.[93] \u00a0Further, all data on a mobile device may not be in one central location requiring logical collections from multiple sources.<\/p>\n<p>[31]\u00a0\u00a0\u00a0\u00a0 Importantly, if the synchronized data is in the form of a backup, the type, currency, and format of the data may vary significantly from what is on the mobile device and may require not only a forensic expert to review and analyze, but special software to decode the data.[94]\u00a0 For example, a user that regularly receives company e-mail on their mobile device, but only periodically backs that device up to a computer or cloud, would have current e-mail easily collected from the device itself, but only out-of-date backups of files in special formats that would require a forensic analyst to translate.[95]<\/p>\n<p style=\"padding-left: 90px\"><strong>a.\u00a0 Cloud-Based<\/strong><\/p>\n<p>[32]\u00a0\u00a0\u00a0\u00a0 The cloud could be one of the locations supplied by vendors of the device such as Apple\u2019s iCloud,[96] Google\u2019s Drive, Microsoft\u2019s SkyDrive; or the cloud could be a subscription service such as DropBox, LiveDrive, BlackBlaze Mozy, Amazon, etc.\u00a0 These services are completely hosted by third-party companies each of which have processes that must be followed if anyone other than the user or the paired device wants to collect the hosted backups.[97]<\/p>\n<p>[33]\u00a0\u00a0\u00a0\u00a0 Each of the major vendors, Apple, Google, RIM and Microsoft, have made provisions for complete or selective backups to be made to their cloud services through cellular or wireless network connections.[98]<\/p>\n<p>[34]\u00a0\u00a0\u00a0\u00a0 As home consumer demand for large storage drives increased, and speeds for residential Internet went up, personal clouds solutions developed, which are generally supplied by hard drive manufacturers as a feature of a home network attached storage (NAS) drive.[99]\u00a0 These solutions from Western Digital, LaCie, Seagate and others allow a central backup to be almost anywhere an Internet connection exists, and may create challenges for coordinating collections.<\/p>\n<p style=\"padding-left: 90px\"><strong>b.\u00a0 Dedicated Server, Application Host, or File Share<\/strong><\/p>\n<p>[35]\u00a0\u00a0\u00a0\u00a0 A dedicated server or share is similar to the personal cloud listed above, but with the key distinction of it being a company owned and managed server or share and likely only used for select applications such as Exchange, Evernote, a CRM or sales application or for centralized management of company owned devices.[100]\u00a0 To further demonstrate the complexities in discussing this issue with prospective clients, a company may host their servers in the cloud (e.g., Rackspace or Amazon virtual servers), or may be using Cloud based private applications such as Office365 or Exchange Online.[101]\u00a0 Unless an MDM is being used by a company to perform complete backups of mobile devices to one of these central servers, only select data would be available from these locations and typically would not include device only data such as call logs, text messages, local pictures or downloaded files.[102]<\/p>\n<p style=\"padding-left: 120px\"><strong>i.\u00a0 Partner Computer or Device<\/strong><\/p>\n<p>[36]\u00a0\u00a0\u00a0\u00a0 A partner computer might be used to synchronize select information to a mobile device or even as a complete backup in the event of loss of the mobile device.\u00a0 iTunes on a local PC or Mac is an example of a computer application that creates a partnership with an iPhone and allows a complete backup of the device to be stored on the computer.[103]\u00a0 An iTunes backup is the closest alternative to an actual logical collection from a physical iPhone.[104]\u00a0 Although the information in iPhone backups is either encrypted or obfuscated in proprietary file formats and naming conventions,[105] others companies like Microsoft or Google, store the backups of files in their original format and have industry standard .XML file formats for data such as call logs and text messages.[106]<\/p>\n<p>[37]\u00a0\u00a0\u00a0\u00a0 Some devices can become partners of other mobile devices through peer-to-peer network and wireless connections such as Bluetooth[107] and Near Field Communications (NFC).[108]\u00a0 Peer devices can be either other smartphones, tablets or computers which might have data such as contacts, pictures or files, or they may be more passive devices with limited usage information.[109]<\/p>\n<p>[38]\u00a0\u00a0\u00a0\u00a0 Regarding each of these locations above, it is important to note that only backed up data can be collected from synchronized device locations, and that volatile data (RAM) and information changed on the device since last synchronization will not be available.[110]\u00a0 Further, some companies, such as Apple, use special formats and mini-databases for the files stored as backups,[111] while others such as Microsoft or Google store the backups of files in their original format and have industry standard .XML file formats for data such as call logs and text messages.[112]<\/p>\n<p style=\"padding-left: 60px\"><strong>3.\u00a0 Physical Imaging\/Full Forensic Copy<\/strong><\/p>\n<p>[39]\u00a0\u00a0\u00a0\u00a0 A forensic image is a bit-level copy of all data on a device in manner that represents the entire state of the device and could clone an exact duplicate with equivalent hardware.[113]\u00a0 Physical imaging, performed while the device has maintained constant power-on and has been isolated from radio communications, can collect volatile memory, current state of running programs etc.[114] \u00a0Physical imaging is limited, as logical collection, to data that are on or in the physical device and memory cards.[115]\u00a0 It should be highlighted that UICC (SIM) cards are a type of memory card like removable memory cards (SD &amp; Micro SD) and need to be included in the collection plan.[116]<\/p>\n<p>[40]\u00a0\u00a0\u00a0\u00a0 The following table will highlight some of the differences in data that is available from each type of collection listed above.[117]<\/p>\n<p>Table 1.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2687\" src=\"https:\/\/jolt.richmond.edu\/files\/2015\/03\/Screen-Shot-2015-03-20-at-1.31.36-PM.png\" alt=\"Screen Shot 2015-03-20 at 1.31.36 PM\" width=\"409\" height=\"487\" srcset=\"https:\/\/blog.richmond.edu\/jolt\/files\/2015\/03\/Screen-Shot-2015-03-20-at-1.31.36-PM.png 409w, https:\/\/blog.richmond.edu\/jolt\/files\/2015\/03\/Screen-Shot-2015-03-20-at-1.31.36-PM-252x300.png 252w, https:\/\/blog.richmond.edu\/jolt\/files\/2015\/03\/Screen-Shot-2015-03-20-at-1.31.36-PM-126x150.png 126w\" sizes=\"auto, (max-width: 409px) 100vw, 409px\" \/><\/p>\n<p>[41]\u00a0\u00a0\u00a0\u00a0 There are multiple ways to collect from mobile devices in a forensically sound manner, and there may be a need for more than one way even in a single case.\u00a0 Forensic collection does not mean only imaging, and imaging does not mean collecting everything.[118] \u00a0Even the seemingly simple options that one would consider for traditional computers or servers quickly become very complex problems when we approach mobile systems.<\/p>\n<p><strong>III.\u00a0 Collection as Part of a Larger Process<\/strong><\/p>\n<p>[42]\u00a0\u00a0\u00a0\u00a0 What we call \u2018collecting\u2019 from a mobile device is actually \u2018processing\u2019[119] and involves a series of steps that are part of an overall process of forensic handling[120] that can be challenged if not handled properly.\u00a0 There are many considerations in certain litigation such as authentication of the actual device (who was the actual user at a point in time), and whether the device is being collected pursuant to a warrant, arrest or consent that go beyond the scope of this writing.<\/p>\n<p>[43]\u00a0\u00a0\u00a0\u00a0 Before we can collect anything, we must identify not only what systems we need to collect from, but how those systems may interact with other systems and make preparations to secure and preserve the data.[121]\u00a0 By being constantly connected, mobile devices are constantly gathering data to internal and external locations.\u00a0 A mobile device can store potentially relevant information on removable memory cards, SIM cards, and internal volatile and non-volatile memory.[122]\u00a0 When certain mobile devices such as the Blackberry go into a \u2018locked\u2019 state, volatile memory is wiped by the device automatically.[123]\u00a0 Additionally, certain methods of unlocking a locked mobile device may require a restart of that device causing certain information to be changed or volatile memory to be cleared.[124]\u00a0 If a device is not protected, incoming calls, text messages, e-mails or application notifications could still change the state of the device even without any malicious intent.[125]<\/p>\n<p>[44]\u00a0\u00a0\u00a0\u00a0 Several very significant issues must be considered when approaching the collection of mobile devices:<\/p>\n<p style=\"padding-left: 30px\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Ownership of the device,<\/p>\n<p style=\"padding-left: 30px\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Expected cooperation of the owner and\/or user (which may not be the same person or entity),<\/p>\n<p style=\"padding-left: 30px\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Synchronized peer devices,<\/p>\n<p style=\"padding-left: 30px\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Remote access\/management and control to the device,<\/p>\n<p style=\"padding-left: 30px\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Technologies and versions, and<\/p>\n<p style=\"padding-left: 30px\">\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Nature of litigation.[126]<\/p>\n<p>[45]\u00a0\u00a0\u00a0\u00a0 Ownership of the device can complicate matters due to the potential for restricted access such as pin codes, encryption, locks, and overall permission.[127] \u00a0In many instances where a company maintains ownership of the device or has established clear policies regarding cooperation by employees with shared use devices this may not be an issue, and even passwords, passcodes, pin codes, or encryption keys may be easily obtained.[128]<\/p>\n<p>[46]\u00a0\u00a0\u00a0\u00a0 As individuals become more aware of and sensitive to the amount of data that their mobile devices contain, they are employing more methods of securing the data and devices through PIN codes, and other encryption.[129]\u00a0 Whether this is a personal choice, or one imposed by corporate policy, the reality is that a majority of users do use some method to protect the data on their device.[130] \u00a0These methods can create challenges, delay, or\u2014in some circumstances\u2014prevent inspection and collection of a mobile device.[131]\u00a0 Collection tools such as Cellebrite and Oxygen support decryption, though an uncooperative or unavailable user could limit collection options if advanced encryption is used with next generation devices such as the \u2018black phone\u2019 or Apple and Google\u2019s most recent operating systems features.[132] \u00a0It is yet to be seen how the courts will ultimately see matters when someone asserts her right to privacy.[133]<\/p>\n<p>[47]\u00a0\u00a0\u00a0\u00a0 Cooperative owners and users significantly reduce risk related to intentional or unintentional loss of data due to delay or external intervention.\u00a0 Sometimes the owner and a user may not be the same entity,[134] and there could be a conflict where technologies or policies were not centrally managed by the company,[135] or if the user feels that the risks associated with lack of cooperation are more favorable than the discovery of information on the mobile device.[136]<\/p>\n<p>[48]\u00a0\u00a0\u00a0\u00a0 Synchronized devices are not limited to just a computer that may periodically back up the device, but may include any device that can remotely change the data on the device even after it is taken into custody.[137]\u00a0 A typical smartphone or tablet will have multiple programs running on it that communicate over a number of networks such as cellular, wireless (Wi-Fi), Bluetooth, and low-frequency near field communications.[138] \u00a0Through any of these methods, or through remote access or control, data can be altered or even completely removed from a device if not secured properly.[139]<\/p>\n<p>[49]\u00a0\u00a0\u00a0\u00a0 The type of device, its operating system, features, and characteristics can have a significant impact not only on how collection may need to be performed, but also on the steps for preservation at time of securing the device.[140]\u00a0 Apple, Samsung, Microsoft, and Blackberry are some of the major players in the mobile device marketspace; however, Google, HP, LG, and others have \u2018smart\u2019 mobile devices with different operating systems, operating system versions, features, power sources, and connectors.[141] \u00a0Sometimes the simplest design feature such an easily removable battery[142] can impact the timing of the preservation of data or accessing simple information like serial numbers.[143]<\/p>\n<p>[50]\u00a0\u00a0\u00a0\u00a0 It should also be mentioned here that security tools and applications must constantly be adapted to account for the constantly changing and ever expanding market of mobile devices.[144] \u00a0The skills for preserving, inspecting, collecting and interpreting mobile data must constantly be honed and even the results of tested tools must be validated and confirmed to maintain the most accurate and defensible presentation of data.[145]<\/p>\n<p>[51]\u00a0\u00a0\u00a0\u00a0 The nature of the litigation or cause for collection is very important and should be a starting point for considering how one may need to approach a collection, and even then everything may not align in your favor.<\/p>\n<p>[52]\u00a0\u00a0\u00a0\u00a0 For typical commercial litigation, where the information sought is related to typical business documents, communications (e.g., e-mail and text messages) and data from managed applications, and the device is managed by a corporate MDM system and policy, collection may be somewhat simplified.[146]<\/p>\n<p>[53]\u00a0\u00a0\u00a0\u00a0 Collection gets more complicated in criminal and certain civil litigation where the use of the mobile device is itself part of the issue, or where specific and detailed analysis of the behaviors of a user or actions need to be performed.[147]<\/p>\n<p>[54]\u00a0\u00a0\u00a0\u00a0 Collection may be merited, even when not specifically requested or implicated, in an effort to provide context or justification.\u00a0 For example, in a personal injury claim where a litigant is seeking damages for future loss of ability and fitness, tracking applications could provide historical evidence of actual activities or a decline since injury.[148]<\/p>\n<p style=\"padding-left: 30px\"><strong>A.\u00a0 Challenges and Complications<\/strong><\/p>\n<p>[55]\u00a0\u00a0\u00a0\u00a0 In some cases, it may be enough to perform a forensically sound logical collection of select targeted information.\u00a0 Sometimes these collections may not even involve the actual mobile device when a reliable current backup or synchronized source of data is available.[149]<\/p>\n<p>[56]\u00a0\u00a0\u00a0\u00a0 In both criminal and many civil cases today, mobile data and even just the evidence of use of a mobile device may be important and may necessitate a more comprehensive evaluation of devices and sources outside of the primary device.[150] \u00a0Criminals are becoming more tech-savvy, with many learning how to hide, encrypt, and even destroy their data on demand.[151]<\/p>\n<p style=\"padding-left: 60px\"><strong>1.\u00a0 Cooperation and Privacy<\/strong><\/p>\n<p>[57]\u00a0\u00a0\u00a0\u00a0 Of course, complications will arise even in simple cases when the user is not cooperative, cannot locate the device, or is subject to other governing privacy regulations such as EU Directive 94\/46\/EC which, in short, is founded on seven basic principles:<\/p>\n<p style=\"padding-left: 30px\">\u2022 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Notice: subjects whose data is being collected should be given notice of such collection.<\/p>\n<p style=\"padding-left: 30px\">\u2022 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Purpose: data collected should be used only for stated purpose(s) and for other purpose.<\/p>\n<p style=\"padding-left: 30px\">\u2022 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Consent: personal data should not be disclosed or shared with third parties without consent from its subject(s).<\/p>\n<p style=\"padding-left: 30px\">\u2022 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security: once collected, personal data should be kept safe and secure from potential abuse, theft, or loss.<\/p>\n<p style=\"padding-left: 30px\">\u2022 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Disclosure: subjects whose personal data is being collected should be informed as to the party or parties collecting such data.<\/p>\n<p style=\"padding-left: 30px\">\u2022 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Access: subjects should granted access to their personal data and allowed to correct any inaccuracies.<\/p>\n<p style=\"padding-left: 30px\">\u2022 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Accountability: subjects should be able to hold personal data collectors accountable for adhering to all seven of these principles.[152]<\/p>\n<p style=\"padding-left: 60px\"><strong>2.\u00a0 Ownership Challenges<\/strong><\/p>\n<p>[58]\u00a0\u00a0\u00a0\u00a0 Even with cooperative users or companies, there can be complications when the two are not one and the same, and there are differing viewpoints.<\/p>\n<p>[59]\u00a0\u00a0\u00a0\u00a0 In 2013, Gartner predicted that by 2017 one half of employers will require employees to supply their own device.[153] \u00a0At the moment, thirty-eight percent of employees in mature markets\u2014such as the US\u2014like to use a single device for both work and personal use,[154] and as much as 46% of companies either ignore or are not aware of the use of personal devices for business use.[155] \u00a0The convenience of using a personal device for both personal and business purposes becomes a problem when users are told that they need to give up their personal device and allow it to be inspected and potentially collected in whole as an image vs. targeted collections.[156]<\/p>\n<p style=\"padding-left: 60px\"><strong>3.\u00a0 Resources<\/strong><\/p>\n<p>[60]\u00a0\u00a0\u00a0\u00a0 The actors who preserve, collect, and review mobile device data are very similar to those who work with connected computing devices. However, their skillsets may be very different, and there is an increased importance in the handling and timing of events.\u00a0 Turning mobile devices off does not ensure that data does not get changed, and introduces the potential that pin codes or other authentication may be triggered when turned back on.[157] \u00a0For example, first responders need to be specially equipped and trained to handle the mobile devices initially.[158] \u00a0Improperly secured or handled devices could potentially be remotely turned back on, wiped, reloaded, or have data altered through synchronization.[159]<\/p>\n<p>[61]\u00a0\u00a0\u00a0\u00a0 Properly trained forensic experts and first responders must be prepared with the skills and tools to act quickly and effectively, whether through the use of radio shielding solutions like a Faraday container to prevent external influence, creating a clone UICC card (e.g. SIM, USIM, RUIM or CSIM) without the ability to communicate with a cellular network, disabling wireless, or preserving the usable state of the device.[160] \u00a0Observations and inquiry must be performed early in the securing of a mobile device.[161]\u00a0 If a mobile device is unlocked and undamaged, has sufficient power or the owner is willing and able to supply any authentication codes, a logical collection might be possible quickly and without additional costs.[162]\u00a0 When devices have authentication codes that are unknown, encryption is enabled or the device is physically damaged, costs and time for collection can go up substantially even for a device with limited in-device memory.[163]<\/p>\n<p>[62]\u00a0\u00a0\u00a0\u00a0 Problematically, there may be a backlog to qualified data extraction facilities or engineers, which can result in the loss or destruction of data through delays before collection.[164]<\/p>\n<p><strong>III.\u00a0 Conclusion<\/strong><\/p>\n<p>[63]\u00a0\u00a0\u00a0\u00a0 Mobile data is unavoidable in modern discovery and will continue to play an increasingly significant role in litigation.\u00a0 Beyond the devices that are the subject of this discussion, the market experiences new innovations almost daily, including new \u201cwearable\u201d technology and the Internet of Things, all of which will be sources of potentially relevant information under the right circumstances.[165]<\/p>\n<p>[64]\u00a0\u00a0\u00a0\u00a0 Attorneys must be prepared to assess and evaluate each new source of information based on the capabilities of the technology and the needs of the case.\u00a0 The legal standard will remain constant: reasonableness given the issues at stake in the litigation.\u00a0 But this is merely the starting point for the legal decisions about collection, which must be informed by the cost and complexity of the activity balanced against the need for the information at issue.\u00a0 Whatever the collection method, it is important to document each step and every decision in the process to defend against potential challenges.<\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<p>* Michael Arnold is a Solutions Program Manager with UnitedLex, a legal process solutions provider.\u00a0 Mr. Arnold has been the Director of Litigation Technology at LeClair Ryan\u2019s Discovery Solutions Practice and with UnitedLex as part of their discovery practice in Richmond, Virginia.\u00a0 He has over 22 years in Information Technology and has been providing technical legal solutions for corporate and law-firm clients since 2004.\u00a0 Mr. Arnold has been involved in all aspects of litigation including forensic collections, complex data analysis and presentation and has attended more than 8 cases in various capacities in local state and federal court.\u00a0 Mr. Arnold is now working on developing new technologies and solutions to help clients respond to and address the needs of the next e-Discovery legal challenges.<\/p>\n<p>** Dennis Kiker is consultant at Granite Legal Systems in Houston, Texas.\u00a0 Mr. Kiker has been a partner in an AmLaw 200 law firm, Director of Professional Services at a major e-Discovery company, and a founding shareholder of his own law firm.\u00a0 He has served as national discovery counsel for one of the largest manufacturing companies in the country, and counseled many others on discovery and information governance-related issues.\u00a0 He is an AV rated attorney admitted to practice in Virginia, Arizona and Florida (retired), and holds a J.D., Magna Cum Laude &amp; Order of the Coif from the University of Michigan Law School.<\/p>\n<p>[1] Indeed, there is confusion even about what the term \u201cforensic\u201d means.\u00a0 Some distinguish between a \u201cforensic image\u201d and a \u201cforensic copy\u201d or \u201cforensically sound\u201d collections.\u00a0 A forensic image refers to a \u201cbit-for-bit copy of the data that exists on the original media, without any additions or deletions.\u201d\u00a0 Ovie L. Carroll, Stephan K. Brannon &amp; Thomas Song, Computer Forensics: Digital Forensic Analysis Methodology, U. S. Attys\u2019 Bull., Jan. 2008, at 1, 2, available at http:\/\/www.justice.gov\/usao\/eousa\/foia_reading_room\/usab5601.pdf, archived at http:\/\/perma.cc\/D7ZG-E9UJ.\u00a0 In other words, every data element on the source media is collected, including program files, system files, fragmented files, and even blank disk space.\u00a0 See R. Lance Fogarty &amp; Gregory Ledenbach, Deleted Computer Data Uncovered, The Tex. Investigator, Spring 2009, at 22, 25, available at http:\/\/www.protegga.com\/wp-content\/uploads\/2014\/10\/Tali-Article.pdf, archived at http:\/\/perma.cc\/XS8E-78J5.\u00a0 The terms \u201cforensic copy\u201d and \u201cforensically sound\u201d generally refer to a targeted, file-level collection that does not include such things as fragmented data.\u00a0 See Thomas Lidbury &amp; Michael Boland, Technology: Forensically Sound Collection of ESI, Inside Counsel (May 11, 2012), http:\/\/www.insidecounsel.com\/2012\/05\/11\/technology-forensically-sound-collection-of-esi, archived at http:\/\/perma.cc\/65QY-WCAE.\u00a0 In reality, any type of information gathering for litigation purposes is \u201cforensic\u201d according to the definition of the term: \u201cpertaining\u00a0to,\u00a0connected\u00a0with,\u00a0or\u00a0used\u00a0in\u00a0courts\u00a0of\u00a0law\u00a0or\u00a0public discussion\u00a0and\u00a0debate.\u201d\u00a0 Forensic, Dictionary.com, http:\/\/dictionary.reference.com\/browse\/forensic?s=t , archived at http:\/\/perma.cc\/63Q8-9TCZ (last visited Mar. 3, 2015).<\/p>\n<p>[2] Mobile Technology Fact Sheet, Pew Res. Center Internet Project, http:\/\/www.pewinternet.org\/fact-sheets\/mobile-technology-fact-sheet\/, archived at http:\/\/perma.cc\/8QTP-RD7K (last visited Mar. 3, 2015).<\/p>\n<p>[3] See Device Ownership Over Time, Pew Res. Center Internet Project, http:\/\/www.pewinternet.org\/data-trend\/mobile\/device-ownership\/, archived at http:\/\/perma.cc\/EVM3-Y74K (last visited Mar. 3, 2015).<\/p>\n<p>[4] See, e.g., Press Release, Gartner, Gartner Predicts by 2017, Half of Employers will Require Employees to Supply Their Own Device for Work Purposes (May 1, 2013), available at http:\/\/www.gartner.com\/newsroom\/id\/2466615, archived at http:\/\/perma.cc\/4Z5N-C8DH.<\/p>\n<p>[5] See, e.g., Mobile Device Analytics: Getting Smart About Smartphones, Deloitte (2013), available at http:\/\/www2.deloitte.com\/content\/dam\/Deloitte\/us\/Documents\/finance\/us-fas-mobile-device-discovery-and-investigations-08162013.pdf, archived at http:\/\/perma.cc\/2GG6-3688.<\/p>\n<p>[6] Norton Rose Fulbright, Litigation Trends Survey Report 35 (2014), available at http:\/\/www.nortonrosefulbright.com\/knowledge\/publications\/115045\/norton-rose-fulbrights-10th-annual-litigation-trends, archived at http:\/\/perma.cc\/CN9L-TB7L.<\/p>\n<p>[7] BDO Consulting, InauguralInside E-Discovery Survey 3 (2014), available at https:\/\/www.bdo.com\/getattachment\/af620fbc-e3c4-46b9-a642-e9332eab5692\/attachment.aspx, archived at https:\/\/perma.cc\/6U4X-CY7U.<\/p>\n<p>[8] See, e.g., Charlie Hiphop, Why the NSA Doesn\u2019t Want You to Have a Blackberry, Cantech Letter (July 23, 2013), http:\/\/www.cantechletter.com\/2013\/07\/why-the-nsa-doesnt-want-you-to-have-a-blackberry0723\/, archived at http:\/\/perma.cc\/CZ6Q-V4DJ.<\/p>\n<p>[9] See Michael Arnold, Column, Collecting Data from Mobile Devices, 40 Litig. 53, 54\u201355 (2013).<\/p>\n<p>[10] Nat\u2019l Highway Traffic Safety Admin., Distracted Driving: Facts and Statistics, Distraction.gov, http:\/\/www.distraction.gov\/get-the-facts\/facts-and-statistics.html, archived at http:\/\/perma.cc\/A8BE-G6X8 (last visited Mar. 3, 2015).<\/p>\n<p>[11] See, e.g., Sheila G. Klauer et al., Distracted Driving and Risk of Road Crashes Among Novice and Experienced Drivers, 370 New Eng. J. Med. 54, 57 (2014), available at http:\/\/www.nejm.org\/doi\/full\/10.1056\/NEJMsa1204142, archived at http:\/\/perma.cc\/PT4V-24L7 (showing that dialing, reaching for, or using a cell phone to send or receive text messages increased the odds of an accident by as much as eight times).<\/p>\n<p>[12] See id. at 55.<\/p>\n<p>[13] See id.<\/p>\n<p>[14] See, e.g., OMG\u2014Is This the End for Texting?, CNBC (Feb. 21, 2014, 4:10 AM), http:\/\/www.cnbc.com\/id\/101406820#, archived at http:\/\/perma.cc\/W7SB-KE4H.<\/p>\n<p>[15] See, e.g., Tom Kaneshige, Think Deleted Text Messages Are Gone Forever?\u00a0 Think Again, CIO (Mar. 11, 2014, 8:00 AM), http:\/\/www.cio.com\/article\/2378005\/byod\/byod-think-deleted-text-messages-are-gone-forever-think-again.html, archived at http:\/\/perma.cc\/2WRD-3M4E.<\/p>\n<p>[16] See Calderon v. Corporacion Puertorriquena De La Salud, 992 F. Supp. 2d 48, 51\u201352 (D. P.R. 2014).<\/p>\n<p>[17] See id. at 52\u201353.<\/p>\n<p>[18] Id. at 52.<\/p>\n<p>[19] Id. at 53.<\/p>\n<p>[20] In re Pradaxa (Dabigatran Etexilate) Prods. Liab. Litig., MDL No. 2385, 3:12-md-02385-DRH-SCW, 2014 U.S. Dist. LEXIS 173674, at *56\u201358 (S.D. Ill. Dec. 9, 2013).<\/p>\n<p>[21] Id. at *56\u201357.<\/p>\n<p>[22] See id. at *62\u201363, *65.<\/p>\n<p>[23] Id. at *68; see also Freres v. Xyngular Corp., No. 2:13-cv-400-DAK-PMW, 2014 U.S. Dist. LEXIS 44116 at *14 (D. Utah Mar. 31, 2014) (ordering production of plaintiffs\u2019 cell phone for inspection and copying); Bailey v. Scoutware, LLC, No. 12-10281, 2014 U.S. Dist. LEXIS 37197, at *17\u201318 (E.D. Mich. Mar. 21, 2014) (allowing forensic inspection of cell phone by plaintiffs\u2019 expert in an attempt to identify allegedly missing text and voicemail messages); Christou v. Beatport, LLC, No. 10-cv-02912-RBJ-KMT, 2013 U.S. Dist. LEXIS 9034, at *37\u201339 (D. Colo. Jan. 23, 2013) (issuing sanctions where defendants took no steps to preserve the text messages on an iPhone that was subsequently lost).<\/p>\n<p>[24] See EEOC v. Original Honeybaked Ham Co., No. 11-cv-02560-MSK-MEH, 2012 U.S. Dist. LEXIS 160285, at *2 (D. Colo. Nov. 7, 2012).<\/p>\n<p>[25] See id. at *7\u20138.<\/p>\n<p>[26] Id. at *3\u20134.<\/p>\n<p>[27] See id. at *7\u20138.<\/p>\n<p>[28] See id.<\/p>\n<p>[29] Rimkus Consulting Grp., Inc. v. Cammarata, 688 F. Supp. 2d 598, 613 (S.D. Tex. Feb. 19, 2010).<\/p>\n<p>[30] Id.; see also Stanley v. Creative Pipe, Inc., 269 F.R.D. 497, 523 (D. Md. Sept. 9, 2010); The Sedona Conference, The Sedona Principles: Second Edition Best Practices Recommendations &amp; Principles for Addressing Electronic Document Production 28 (Jonathan M. Redgrave et al. eds., 2007) [hereinafter THE SEDONA PRINCIPLES], available at http:\/\/www.sos.mt.gov\/Records\/committees\/erim_resources\/A%20-%20Sedona%20Principles%20Second%20Edition.pdf, archived at http:\/\/perma.cc\/9HGB-C3YE.<\/p>\n<p>[31] See Nola Spice Designs, LLC v. Haydel Enters., No. 12-2515, 2013 U.S. Dist. LEXIS 108872, at *2\u20133 (E.D. La. Aug. 2, 2013).<\/p>\n<p>[32] Id. at *2\u20133.<\/p>\n<p>[33] Id. at *3.<\/p>\n<p>[34] Id. at *3\u20136.<\/p>\n<p>[35] Id. at *6 (quoting John B. v. Goetz, 531 F.3d 448, 459-60 (6th Cir. 2008) (internal citations omitted)).<\/p>\n<p>[36] Nola Spice Designs, 2013 U.S. Dist. LEXIS 108872, at *7.<\/p>\n<p>[37] See John B. v. Goetz, 531 F.3d 448, 461 (6th Cir. 2008).<\/p>\n<p>[38] See id. at 451\u201352.<\/p>\n<p>[39] See id. at 451.<\/p>\n<p>[40] Id. at 451.<\/p>\n<p>[41] See id. at 456\u201359.<\/p>\n<p>[42] John B., 531 F.3d at 459.<\/p>\n<p>[43] Id. at 460 (quoting The Sedona Principles, supra note 30, at 34, 47.<\/p>\n<p>[44] See John B., 531 F.3d at 460.<\/p>\n<p>[45] Id. at 460\u201361.<\/p>\n<p>[46] See Lee v. Stonebridge Life Ins. Co., No. 11-cv-43 RS, 2013 U.S. Dist. LEXIS 106654, at *2 (N.D. Cal. July 30, 2013).<\/p>\n<p>[47] See Beth Winegarner, Stonebridge Settles Spam Text Case with 60K Plaintiffs, Law360, http:\/\/www.law360.com\/articles\/524843\/stonebridge-settles-spam-text-case-with-60k-plaintiffs, archived at http:\/\/perma.cc\/3862-H4M6 (last visited Mar. 6, 2015).<\/p>\n<p>[48] See Lee, 2013 U.S. Dist. LEXIS 106654, at *2.<\/p>\n<p>[49] See id. at *7\u20138.<\/p>\n<p>[50] Id. at *2\u20133 (quoting Fed. R. Civ. P. 34(a)(1)(A)).<\/p>\n<p>[51] Id. at *4.<\/p>\n<p>[52] Id. at *4\u20135, *7; see also Bradfield v. Mid-Continent Cas. Co., No. 5:13-cv-222-Oc-10PRL, 2014 U.S. Dist. LEXIS 128677, at *11\u201312, *14\u201315 (M.D. Fla. Sept. 15, 2014) (denying request for forensic inspection of plaintiff\u2019s counsel\u2019s computer where there was no evidence that the information sought was not available from some other source, the \u201cparticular information sought [was] known to actually exist,\u201d and there was no evidence that information had been wrongfully withheld).<\/p>\n<p>[53] See Olney v. Job.com, No. 1:12-cv-01724-LJO-SKO, 2014 U.S. Dist. LEXIS 152140, at *67 (E.D. Cal. Oct. 24, 2014).<\/p>\n<p>[54] See id. at *6\u20137.<\/p>\n<p>[55] See id. at *7\u20138.<\/p>\n<p>[56] See id. at *9\u201326.<\/p>\n<p>[57] See id. at *30\u201334, *36\u201342.<\/p>\n<p>[58] Olney, 2014 U.S. Dist. LEXIS 152140, at *8.<\/p>\n<p>[59] See id. at *10.<\/p>\n<p>[60] Id. at *24\u201327.<\/p>\n<p>[61] Id. at *32.<\/p>\n<p>[62] See Ackerman v. PNC Bank, No. 12-CV-42 (SRN\/JSM), 2014 U.S. Dist. LEXIS 8301, at *5\u20137 (D. Minn. Jan. 23, 2014).<\/p>\n<p>[63] Id. at *2, *5\u20136.<\/p>\n<p>[64] Id. at *6 (quoting Fed. R. Civ. P. 34(b)(2)(E)(i)\u2013(ii)).<\/p>\n<p>[65] See ESI &amp; Data Hosting, DLSDiscovery, http:\/\/www.dlsdiscovery.net\/esi_data_hosting.html, archived at http:\/\/perma.cc\/D2V2-2ZEH (last visited Feb. 9, 2015).<\/p>\n<p>[66] See, e.g., Billing and Payments, Understanding the Bill, Verizon, http:\/\/www.verizonwireless.com\/support\/view-bill-online-faqs\/, archived at http:\/\/perma.cc\/VCQ9-ZCEK (last visited Feb. 9, 2015).<\/p>\n<p>[67] See id.<\/p>\n<p>[68] See Cell Phone Tower Triangulation, Int\u2019l Investigators Incorporated, http:\/\/www.iiiweb.net\/forensic-services\/cell-phone-tower-triangulation\/, archived at http:\/\/perma.cc\/49AP-TPMP (last visited Feb. 9, 2015).<\/p>\n<p>[69] See, e.g., Christopher Null, Mobile Printing: A Guide for the BYOD World, PCWorld (Sept. 16, 2013, 3:01 AM), http:\/\/www.pcworld.com\/article\/2048634\/mobile-printing-a-guide-for-the-byod-world.html, archived at http:\/\/perma.cc\/3V9E-AMYU.<\/p>\n<p>[70] See Mark Lenetsky, eDiscovery: Collection of Text Messages, Adaptable Technologies LLC, http:\/\/adaptable-tech.com\/ediscovery-r-link\/ediscovery-collection-of-text-messages\/, archived at http:\/\/perma.cc\/GW7P-XSEM (last visited Mar. 5, 2015).<\/p>\n<p>[71] See Cindy Murphy, Cellular Phone Evidence: Data Extraction and Documentation, available at https:\/\/mobileforensics.files.wordpress.com\/2010\/07\/cell-phone-evidence-extraction-process-development-1-1-8.pdf, archived at https:\/\/perma.cc\/NWN6-A6JX.<\/p>\n<p>[72] See id.<\/p>\n<p>[73] See Paul Henry, Quick Look\u2014Cellebrite UFED Using Extract Phone Data &amp; File System Dump, SANS Digital Forensics &amp; Incident Response (Sept. 22, 2010, 6:16 PM), http:\/\/digital-forensics.sans.org\/blog\/2010\/09\/22\/digital-forensics-quick-cellebrite-ufed-extract-phone-data-file-system-dump\/, archived at http:\/\/perma.cc\/CB63-6XNC.<\/p>\n<p>[74] See Tim Proffitt, Forensic Analysis on iOS Devices 3\u20134, 6\u20139 (2012), available at http:\/\/www.sans.org\/reading-room\/whitepapers\/forensics\/forensic-analysis-ios-devices-34092\/ forensic-analysis-ios-devices-34092 (1).pdf, archived at http:\/\/perma.cc\/4PL3-9T5E.<\/p>\n<p>[75] See id. at 10\u201311.<\/p>\n<p>[76] See Write Blockers, Forensics Wiki, http:\/\/www.forensicswiki.org\/wiki\/Write_Blockers, archived at http:\/\/perma.cc\/6VXA-9C5L (last visited Mar. 6, 2015).<\/p>\n<p>[77] See id.<\/p>\n<p>[78] See, e.g., Data Acquisition &amp; Preservation, Access Data, http:\/\/accessdata.com\/services\/digital-forensics\/data-aquisition-preservation, archived at http:\/\/perma.cc\/3EPB-JZHA (last visited Mar. 6, 2015); SAFECOPY, Pinpoint Labs, http:\/\/pinpointlabs.com\/sc2.html, archived at http:\/\/perma.cc\/38QX-NDNY (last visited Mar. 6, 2015); TOUCHCOPY, Wide Angle Software, http:\/\/www.wideanglesoftware.com\/touchcopy\/index.php, archived at http:\/\/perma.cc\/7JBL-GRNJ (last visited Mar. 6, 2015).<\/p>\n<p>[79] See, e.g., Mary McMahon, What Is a Jailbroken Phone?, wiseGEEK, http:\/\/www.wisegeek.com\/what-is-a-jailbroken-phone.htm, archived at http:\/\/perma.cc\/6ZHX-LR6B (last modified Feb. 15, 2015).<\/p>\n<p>[80] See id.<\/p>\n<p>[81] See, e.g., Murphy, supra note 71.<\/p>\n<p>[82] See, e.g., Henry, supra note 73.<\/p>\n<p>[83]\u00a0 See Proffitt, supra note 74, at 9.<\/p>\n<p>[84] See id.<\/p>\n<p>[85] See David Ashfield, Mobile Device Forensics: Data Acquisition Types, CCL Group (May 19, 2014), http:\/\/www.cclgroupltd.com\/mobile-device-forensics-data-acquisition-types\/, archived at http:\/\/perma.cc\/C5RQ-FLW7.<\/p>\n<p>[86] See id.<\/p>\n<p>[87] See What Are Our Best Options for Collecting and Synchronizing GIS Field Data?, WebMapSolutions, http:\/\/www.webmapsolutions.com\/what-are-our-best-options-for-collecting-and-synchronizing-gis-field-data, archived at http:\/\/perma.cc\/C8AK-QVW4 (last visited Feb. 18, 2015).<\/p>\n<p>[88] See Vangie Beal, What Is Mobile Device Management (MDM)?, Webopedia, http:\/\/www.webopedia.com\/TERM\/M\/mobile_device_management.html, archived at http:\/\/perma.cc\/7FVM-2TZ7 (last visited Mar. 6, 2015).<\/p>\n<p>[89] See Carla Schroder, 6 Data Backup Devices for Small Businesses, Small Business Computing.com (Aug. 4, 2014), http:\/\/www.smallbusinesscomputing.com\/biztools\/6-data-backup-devices-for-small-businesses.html, archived at http:\/\/perma.cc\/6EVR-GHSF; see also The Difference Between Cloud Hosting and Dedicated Servers and What\u2019s Right for You, steadfast, http:\/\/www.steadfast.net\/blog\/index.php\/cloud\/he-difference-between-cloud-hosting, archived at http:\/\/perma.cc\/U82P-TVZ7 (last visited Mar. 6, 2015).<\/p>\n<p>[90] See, e.g., Rene Millman, Smartphones &amp; Tablets Remotely Wiped in UK Police Custody, ITPro (Oct. 10, 2014), http:\/\/www.itpro.co.uk\/security\/23273\/smartphones-tablets-remotely-wiped-in-uk-police-custody, archived at http:\/\/perma.cc\/EH3U-5DCB.<\/p>\n<p>[91] See, e.g., Supreme Court Watch: Ten Key Issues from the Riley Opinion Protecting Cell Phone Data Seized During an Arrest, Fed. Evidence Rev. (June 30, 2014), http:\/\/federalevidence.com\/blog\/2014\/june\/supreme-court-watch-cell-phone-content-protected-under-fourth-amendment, archived at http:\/\/perma.cc\/DR9P-NZ8P.<\/p>\n<p>[92] See, e.g., Computer Tips and Tricks, Gadgets, How-To, Life-2.0 Style, Tech Buzz (Mar. 21, 2009), http:\/\/www.techbuzz.in\/can-two-people-be-logged-into-the-same-facebook-account-at-the-same-time.php, archived at http:\/\/perma.cc\/ZDJ7-77C2; see also Remote Wipe Overview, Dropbox, https:\/\/www.dropbox.com\/en\/help\/4227, archived at https:\/\/perma.cc\/743T-JMJJ (last visited Mar. 6, 2015).<\/p>\n<p>[93] See, e.g., Create and Delete iPhone, iPad, and iPod Touch Backups in iTunes, Apple, https:\/\/support.apple.com\/en-us\/HT204269, archived at https:\/\/perma.cc\/RT4L-HXU4 (last visited Mar. 6. 2015).<\/p>\n<p>[94] See iCloud Security and Privacy Overview, Apple, https:\/\/support.apple.com\/en-us\/HT202303, archived at https:\/\/perma.cc\/FL7M-NQTV (last visited Jan. 27, 2015). \u00a0Microsoft offers a similar service.\u00a0 See Back up My Stuff, Windows Phone, http:\/\/www.windowsphone.com\/en-us\/how-to\/wp8\/settings-and-personalization\/back-up-my-stuff, archived at http:\/\/perma.cc\/3P9H-RXNM (last visited Mar. 6, 2015).\u00a0 Android users can download apps, such as inDefend, to back up their personal information.\u00a0 See inDefend Mobile Backup, Google, https:\/\/play.google.com\/store\/apps\/details?id=com.dataresolve.android.security.backup&amp;hl=en, archived at https:\/\/perma.cc\/GSQ7-SXNL (last visited Jan. 27, 2015).\u00a0 Except using the Link function on a corporate Blackberry server, Blackberry does not backup e-mail, contacts or calendars. See User Guide: BlackBerry Link for Windows 1.0, Back Up Your Device Data, BlackBerry, http:\/\/docs.blackberry.com\/en\/smartphone_users\/deliverables\/49304\/lym1340633934452.jsp, archived at http:\/\/perma.cc\/X4XE-ZGPF (last visited Mar. 6, 2015).<\/p>\n<p>[95] See Satish B., iPhone Forensics\u2014Analysis of iOS 5 Backups: Part 1, Infosec Inst. (May 3, 2012), http:\/\/resources.infosecinstitute.com\/ios-5-backups-part-1\/, archived at http:\/\/perma.cc\/7N6N-9LQL.<\/p>\n<p>[96] See Thomas J. Trappler, When There\u2019s a Third Party in the Cloud, Computerworld (July 30, 2012, 10:42 AM), http:\/\/www.computerworld.com\/article\/2505135\/cloud-computing\/when-there-s-a-third-party-in-the-cloud.html, archived at http:\/\/perma.cc\/45KH-HD4D.<\/p>\n<p>[97] See, e.g., Back Up My Stuff, supra note 94; BlackBerry Business Cloud Services, BlackBerry, http:\/\/us.blackberry.com\/enterprise\/products\/cloud-services\/overview.html, archived at http:\/\/perma.cc\/DEP4-EJ6Z (last visited Mar. 6, 2015); see also iCloud: iCloud Storage and Backup Overview, Apple, https:\/\/support.apple.com\/kb\/PH12519?viewlocale=en_US&amp;locale=en_US (last visited Mar. 6, 2015), archived at https:\/\/perma.cc\/BFB4-VBDA.<\/p>\n<p>[98] See, e.g., sources cited supra note 97.<\/p>\n<p>[99] See, e.g., Margaret Rouse, What Is Network-Attached Storage (NAS)?, Search Storage (Aug. 2014), http:\/\/searchstorage.techtarget.com\/definition\/network-attached-storage, archived at http:\/\/perma.cc\/RN4Q-32YJ.<\/p>\n<p>[100] See, e.g., Margaret Rouse, Dedicated Server Definition, TechTarget (Sept. 2005), http:\/\/searchsoa.techtarget.com\/definition\/dedicated-server, archived at http:\/\/perma.cc\/BSX6-XR6D.<\/p>\n<p>[101] See, e.g., Barney Beal, Public vs. Private Cloud Applications: Two Critical Differences, TechTarget (May 2012), http:\/\/searchcloudapplications.techtarget.com\/feature\/Public-vs-private-cloud-applications-Two-critical-differences, archived at http:\/\/perma.cc\/D6WB-S68S.<\/p>\n<p>[102] See Why Mobile Device Management, 2X, http:\/\/www.2x.com\/mdm\/why-mobile-device-management\/, archived at http:\/\/perma.cc\/4824-7JSE (last visited Mar. 6, 2015).<\/p>\n<p>[103] Satish B., Forensic Analysis of iPhone Backups, Exploit DB, http:\/\/www.exploit-db.com\/wp-content\/themes\/exploit\/docs\/19767.pdf, archived at http:\/\/perma.cc\/39FT-EPLV (last visited Mar. 16, 2015).<\/p>\n<p>[104] See Bader &amp; Baggili, iPhone 3GS Forensics: Logical Analysis Using Apple iTunes Backup Utility, 4 Small Scale Digital Device Forensics J. 1 (2010), available at http:\/\/citeseerx.ist.psu.edu\/viewdoc\/download?doi=10.1.1.185.4439&amp;rep=rep1&amp;type=pdf, archived at http:\/\/perma.cc\/N4AS-J6DV.<\/p>\n<p>[105] See, e.g., Selena Ley, Processing iPhone \/ iPod Touch Backup Files on a Computer, The Apple Examiner, http:\/\/www.appleexaminer.com\/iPhoneiPad\/iPhoneBackup\/iPhoneBackup.html, archived at http:\/\/perma.cc\/X7VK-HBRH (last visited Mar. 5, 2015).<\/p>\n<p>[106] See , e.g., FAQ about SMS Backup &amp; Restore, AndroidStuff (Apr. 18, 2012), http:\/\/android.riteshsahu.com\/misc\/faqs-about-sms-backup-restore, archived at http:\/\/perma.cc\/UMR9-U477.<\/p>\n<p>[107] See, e.g., Fast Facts, Bluetooth SIG, Inc., http:\/\/www.bluetooth.com\/Pages\/Fast-Facts.aspx, archived at http:\/\/perma.cc\/B5JN-ANJE (last visited Mar. 3, 2015).<\/p>\n<p>[108] See, e.g., Near Field Communication, http:\/\/www.nearfieldcommunication.org, archived at http:\/\/perma.cc\/EXM3-GT56 (last visited Mar. 3, 2015).<\/p>\n<p>[109] Peer devices go beyond just passive ear pieces and are a growing market with the increase in \u2018wearable\u2019 technologies such as smart watches, fitness bands, health meters and even pain management devices and can be important in litigation due to their ability to either allow files to move from the device without traditional e-mail or text transmissions or for the data that they might supply.\u00a0 See Sean Greene, Electronic Evidence Expert Witness: Will Fitbit and Crowdsourcing* Change Personal Injury Cases?, Evidence Solutions, Inc., http:\/\/www.evidencesolutions.com\/web\/Digital-Evidence-Articles\/fitbit-data-goes-to-court-electronic-evidence-expert.html, archived at http:\/\/perma.cc\/Z58Z-GQET (last visited Mar. 3, 2015).<\/p>\n<p>[110] See Rick Ayers et al., Nat\u2019l Inst. of Stds. &amp; Tech., U.S. Dept. of Commerce, Guidelines on Mobile Device Forensic 3, 6 (Special Pub. 800-101, Rev. 1, May 2014), available at http:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-101r1.pdf, archived at http:\/\/perma.cc\/U7SV-DWU9.<\/p>\n<p>[111] See, e.g., Selena Ley, Processing iPhone \/ iPod Touch Backup Files on a Computer, The Apple Examiner, http:\/\/www.appleexaminer.com\/iPhoneiPad\/iPhoneBackup\/iPhoneBackup.html, archived at http:\/\/perma.cc\/K3KW-K3RH (last visited Mar. 5, 2015).<\/p>\n<p>[112] See, e.g., FAQ about SMS Backup &amp; Restore, AndroidStuff (Apr. 18, 2012), http:\/\/android.riteshsahu.com\/misc\/faqs-about-sms-backup-restore, archived at http:\/\/perma.cc\/TM2Y-YH8W.<\/p>\n<p>[113] What is Forensic Hard Drive Imaging, Forensicon Computer Forensic Specialists , http:\/\/www.forensicon.com\/resources\/articles\/what-is-forensic-hard-drive-imaging\/, archived at http:\/\/perma.cc\/3NUC-XM9T (last visited Mar. 3, 2015).<\/p>\n<p>[114] Kristine Amari, Techniques and Tools for Recovering and Analyzing Data from Volatile Memory, SANS Institute InfoSec Reading Room (Mar. 26, 2009), available at www.sans.org\/reading-room\/whitepapers\/forensics\/techniques-tools-recovering-analyzing-data-volatile-memory-33049, archived at http:\/\/perma.cc\/5B8D-8EDK.<\/p>\n<p>[115] See Rick Ayers et al., supra note 110, at 46.<\/p>\n<p>[116] Id. at 7.<\/p>\n<p>[117] See supra notes 113\u201316 and accompanying text.<\/p>\n<p>[118] Matthew Nelson, The Top 3 Forensic Data Collection Myths in eDiscovery, Symantec eDiscovery Blog (Aug. 7, 2013), http:\/\/www.symantec.com\/connect\/blogs\/top-3-forensic-data-collection-myths-ediscovery, archived at http:\/\/perma.cc\/ZL5C-EC7L.<\/p>\n<p>[119] See, e.g., Murphy, supra note 71.<\/p>\n<p>[120] See Ayers et al., supra note 110, at 2\u20133.<\/p>\n<p>[121] See Murugiah Souppaya &amp; Karen Scarfone, NIST Special Publication 800-124 Revision 1: Guidelines for Managing the Security of Mobile Devices in the Enterprise 5\u20136 (2013), available at http:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-124r1.pdf, archived at http:\/\/perma.cc\/FF9G-B38U.<\/p>\n<p>[122] See Ayers et al., supra 110, at 6\u20138, 10\u201311.<\/p>\n<p>[123] Any Way to Prevent Device Wipe after Failed password Attempts in BB10?, Crackberry (May 22, 2013), http:\/\/forums.crackberry.com\/blackberry-z10-f254\/any-way-prevent-device-wipe-after-failed-password-attempts-bb10-810021\/, archived at http:\/\/perma.cc\/Z9TV-L3U4.<\/p>\n<p>[124] Ensure Mobile Device Security, 2X MDM, http:\/\/www.2x.com\/mdm\/mobile-device-security\/, archived at http:\/\/perma.cc\/V489-LJ2W (last visited Mar. 3, 2015).<\/p>\n<p>[125] Jason Gonzalez &amp; James Hung, Stroz Friedberg LLC, Mobile Device Forensics: A Brave New World?, Bloomberg Law Reports, http:\/\/www.strozfriedberg.com\/files\/Publication\/224ca0f8-5101-4e1b-938a-4d4b128ad5ed\/Presentation\/PublicationAttachment\/ef4a28ad-ff7d-4014-aea8-80505789b86c\/Mobile%20Device%20Forensics_%20A%20Brave%20New%20World.pdf, archived at http:\/\/perma.cc\/ZR43-D9RF (last visited Mar. 3, 2015).<\/p>\n<p>[126] See Michael Arnold, Collecting Data from Mobile Devices, ABA, http:\/\/apps.americanbar.org\/litigation\/litigationnews\/trial_skills\/110113-tips-collecting-data-mobile-device.html, archived at http:\/\/perma.cc\/EK2D-U27L (last visited Mar. 3, 2015).<\/p>\n<p>[127] See, e.g., id.<\/p>\n<p>[128] See, e.g., id.<\/p>\n<p>[129] Mobile Devices, Stay Smart Online, http:\/\/www.staysmartonline.gov.au\/mobile_devices, archived at http:\/\/perma.cc\/QW37-DKCC (last visited Mar. 3, 2015).<\/p>\n<p>[130] See, e.g., Donna Tapellini, Smart Phone Thefts Rose to 3.1 Million Last Year, Consumer Reports Finds, Consumer Reps. (May 28, 2014, 4:00 PM), http:\/\/www.consumerreports.org\/cro\/news\/2014\/04\/smart-phone-thefts-rose-to-3-1-million-last-year\/index.htm, archived at http:\/\/perma.cc\/RA4M-J7HP.<\/p>\n<p>[131] See Ayers et al., supra 110, at 43.<\/p>\n<p>[132] See, e.g., James B. Comey, Director, Federal Bureau of Investigation, Remarks at the Brookings Inst. (Oct. 16, 2014), available at http:\/\/www.fbi.gov\/news\/speeches\/going-dark-are-technology-privacy-and-public-safety-on-a-collision-course, archived at http:\/\/perma.cc\/HGK5-UPMV.<\/p>\n<p>[133] See Andy Greenberg, Google and Apple Won\u2019t Unlock Your Phone, But a Court Can Make You Do It, Wired (Sept. 22, 2014 6:30 AM), http:\/\/www.wired.com\/2014\/09\/google-apple-wont-unlock-phone-court-can-make\/, archived at http:\/\/perma.cc\/4L8Y-MVDZ.<\/p>\n<p>[134] See, e.g., Ex-Lawyer Tells Goffer Jury He Traded 3Com Merger Tips for Cash, Bloomberg (May 19, 2011, 12:01 AM), http:\/\/www.bloomberg.com\/news\/2011-05-19\/goffer-trial-witness-says-he-traded-merger-tips-for-cash-filled-envelopes.html, archived at http:\/\/perma.cc\/C4AG-S3WR.<\/p>\n<p>[135] Id.<\/p>\n<p>[136] See, e.g., Sentencing Memorandum on Behalf of Raj Rajaratnam, United States v. Raj Rajaratnam, 2011 U.S. Dist. LEXIS 21062, at 59 (S.D.N.Y. Aug. 9, 2011), available at http:\/\/www.law.du.edu\/documents\/corporate-governance\/criminal\/rajaratnam\/Sentencing-Memorandum-on-Behalf-of-Raj-Rajaratnam-US-v-Rajaratnam-S1-09-CR-1184-SD-NY-August-9-2011.pdf, archived at http:\/\/perma.cc\/ZKA7-D5F7.<\/p>\n<p>[137] See, e.g., Arnold, supra note 126.<\/p>\n<p>[138] Gonzalez, supra note 125.<\/p>\n<p>[139] See, e.g., Rene Millman, Smartphones &amp; Tablets Remotely Wiped in UK Police Custody, ITPro (Oct. 10, 2014), http:\/\/www.itpro.co.uk\/security\/23273\/smartphones-tablets-remotely-wiped-in-uk-police-custody, archived at http:\/\/perma.cc\/4TE6-TVKH; Jane Wakefield, Devices Being Remotely Wiped in Police Custody, BBC News (Oct. 9, 2014, 8:30 AM), http:\/\/www.bbc.com\/news\/technology-29464889, archived at http:\/\/perma.cc\/RZS6-29KX.<\/p>\n<p>[140] See Arnold, supra note 126.<\/p>\n<p>[141] See, e.g., Jessica Dolcourt, Best Phones of 2015, Cnet (Feb. 20, 2015, 11:16 AM), http:\/\/www.cnet.com\/topics\/phones\/best-phones\/, archived at http:\/\/perma.cc\/KR96-B6PH; see also Thomas Halleck, Google Planning Two Nexus Smartphones for 2015: Rumor Pegs LG For New Nexus 6 (Mar. 2, 2015, 7:53 PM), http:\/\/www.ibtimes.com\/google-planning-two-nexus-smartphones-2015-rumor-pegs-lg-new-nexus-6-1833718, archived at http:\/\/perma.cc\/87EN-RUWD.<\/p>\n<p>[142] See, e.g., How to Remove the Battery from an iPhone, wikiHow, http:\/\/www.wikihow.com\/Remove-the-Battery-from-an-iPhone, archived at http:\/\/perma.cc\/7BED-EHFA (last visited Jan. 28, 2015) (noting nine steps are needed to remove the iPhone 5 battery).<\/p>\n<p>[143] See Ayers et al., supra note 110, at 41.<\/p>\n<p>[144] See Souppaya &amp; Scarfone, supra note 121, at 12.<\/p>\n<p>[145] See Murphy, supra note 71, at 9.<\/p>\n<p>[146] See, e.g., CDW, Mobile Device Management:\u00a0 Not What it Used to Be 4 (2012), available at http:\/\/webobjects.cdw.com\/webobjects\/media\/pdf\/108281-WP-Mobile-Device-Mgt.pdf, archived at http:\/\/perma.cc\/KHT6-D8TK; see also Arnold, supra note 126.<\/p>\n<p>[147] See Arnold, supra note 126.<\/p>\n<p>[148] See Parmy Olsen, Fitbit Data Now Being Used In The Courtroom, Forbes (Nov. 11, 2014, 4:10 PM), http:\/\/www.forbes.com\/sites\/parmyolson\/2014\/11\/16\/fitbit-data-court-room-personal-injury-claim\/, archived at http:\/\/perma.cc\/MFG8-CCVV.<\/p>\n<p>[149] See Arnold, supra note 126.<\/p>\n<p>[150] See id.<\/p>\n<p>[151] See Tim Crushing, DOJ Whines That A Warrant To Search A Mobile Phone Makes It More Difficult To Catch Criminals, TechDirt (Apr. 24, 2014, 12:48 PM), https:\/\/www.techdirt.com\/articles\/20140423\/15081827008\/government-argues-that-warrant-requirement-cell-phone-searches-does-nothing-keep-cops-catching-bad-guys.shtml, archived at https:\/\/perma.cc\/8UDA-EXDY.<\/p>\n<p>[152] See Protection of personal data, European Commission (Apr. 9, 2014), available at http:\/\/ec.europa.eu\/justice\/data-protection\/, archived at http:\/\/perma.cc\/VG4A-RDF9.<\/p>\n<p>[153] See Press Release, Gartner, Inc., Gartner Predicts by 2017, Half of Employers will Require Employees to Supply Their Own Device for Work Purposes (May 1, 2013), available at http:\/\/www.gartner.com\/newsroom\/id\/2466615, archived at http:\/\/perma.cc\/ZV7K-RAYY.<\/p>\n<p>[154] See Brian Proffitt, Worried Workers: BYOD Or You\u2019re SOL [Infographic], readwrite (Dec. 6, 2012), http:\/\/readwrite.com\/2012\/12\/06\/pause-economy-linked-to-bring-your-own-device-use, archived at http:\/\/perma.cc\/Q7X3-RYY9.<\/p>\n<p>[155] See id.; see also Businesses Unprepared to Support New Mobile Ways of Working, Citrix (Nov. 21, 2011), http:\/\/www.citrix.com\/news\/announcements\/nov-2011\/businesses-unprepared-to-support-new-mobile-ways-of-working.html, archived at http:\/\/perma.cc\/7AHJ-ARDP.<\/p>\n<p>[156] Haman Allen &amp; David Herman, Challenges of Mobile Devices, BYOD and EDiscovery, Law Technology Today (Sept. 19, 2014), http:\/\/www.lawtechnologytoday.org\/2014\/09\/challenges-of-mobile-devices-byod-and-ediscovery\/, archived at http:\/\/perma.cc\/4HPP-MDHY.<\/p>\n<p>[157] See Gonzalez, supra note 125.<\/p>\n<p>[158] See Ayers et al., supra note 110, at 27.<\/p>\n<p>[159] See Arnold, supra note 126.<\/p>\n<p>[160] See Ayers et al., supra note 110, at 29.<\/p>\n<p>[161] See Jill Griset &amp; Melissa Laws, Navigating A Case Through E-discovery, McGuire Woods LLP 2 (2012), http:\/\/www.mcguirewoods.com\/news-resources\/publications\/navigating-e-discovery.pdf, archived at http:\/\/perma.cc\/C4A7-LBW8.<\/p>\n<p>[162] See Ayers et al., supra note 110, at 35\u201337; Digital Mountain, Inc, Taking the First Step\u2014Data Preservation 2 (2009), available at http:\/\/digitalmountain.com\/fullaccess\/Article5.pdf, archived at http:\/\/perma.cc\/S77J-UEXF.<\/p>\n<p>[163] See Arnold, supra note 126.<\/p>\n<p>[164] See Millman, supra note 90.<\/p>\n<p>[165] See Ted Samson, How Wearable Tech Will Fuel The Internet of Things, InfoWorld (June 5, 2013), http:\/\/www.infoworld.com\/article\/2614798\/mobile-technology\/how-wearable-tech-will-fuel-the-internet-of-things.html, archived at http:\/\/perma.cc\/3DBN-CWHY.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>DownloadPDF Cite as: Michael Arnold &amp; Dennis R. Kiker, The Big Data Collection Problem of Little Mobile Devices, 21 Rich. J.L. &amp; Tech. 10 (2015), http:\/\/jolt.richmond.edu\/v21i3\/article10.pdf. by Michael Arnold* &amp; Dennis R. Kiker** [1]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 There should be little question that mobile device-based data are discoverable if relevant.\u00a0 However, as was the case with ordinary computer-based [&hellip;]<\/p>\n","protected":false},"author":4287,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[1228],"tags":[],"class_list":["post-2678","post","type-post","status-publish","format-standard","hentry","category-articles"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-Hc","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/2678","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/4287"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=2678"}],"version-history":[{"count":0,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/2678\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=2678"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=2678"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=2678"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}