SDNY
eDiscovery in the Southern District of New York
Preservation, collection, processing, review support and production for matters in SDNY. Workflows are designed to the Federal Rules of Civil Procedure and to the schedule the assigned chambers actually sets.
The engagement
What the SDNY eDiscovery engagement covers
The Southern District of New York carries a heavy commercial and financial-crime docket, and the eDiscovery expectations of both the bench and opposing counsel are calibrated accordingly. Matters commonly involve a mix of Microsoft 365 and Google Workspace tenants, Slack and Teams workspaces, structured data from ERP and trading systems, personal-device data collected under a targeted protocol, and cloud audit-log evidence.
GDF supports SDNY matters end to end on the technical side: preservation on notice, defensible collection at the source, processing that respects the FRCP Rule 34(b)(2)(E) production form obligations, review-platform loading (Relativity, Reveal, Everlaw, Nuix Discover, DISCO), production in the form the receiving party actually uses, and, where the matter requires it, expert-witness testimony on the technical record.
The engagement is scoped up front against the SDNY chambers' individual practices and the Rule 26(f) discussion, so preservation and collection do not run past what the matter actually needs. Where the case is assigned to a Magistrate Judge for discovery, the scope conversation is calibrated to that Magistrate's ESI practice.
Scope
Legal holds and preservation
Written hold notices, custodian interviews focused on sources of ESI, and preservation-in-place or targeted preservation collection depending on the source. Cloud tenants are placed on hold at the platform level (Microsoft Purview eDiscovery, Google Vault, Slack eDiscovery API) where the environment supports it.
Defensible collection at the source
Custodian mobile devices (iOS and Android) collected with forensic tools that acknowledge modern platform constraints (Advanced Logical, checkm8 where the device supports it, cloud-backup extractions, third-party app data where present). Cloud mailboxes, chat, files and admin logs collected via first-party APIs where possible, third-party connectors where not.
Processing and analytics
Deduplication (MD5 and email-thread), near-duplicate and email-thread suppression, technology-assisted review workflows (continuous active learning where the matter supports it), foreign-language identification and translation staging, and structured-data normalization for ERP and trading data.
Review-platform loading and hosting
Loading to Relativity, Reveal, Everlaw, Nuix Discover, DISCO or the receiving party's chosen platform. Where GDF hosts the review, access is controlled to the review team specified by counsel and audit trails cover every access event.
Production
Load files (Concordance DAT, Relativity RDX, EDRM XML) matching the receiving party's specifications. TIFF with searchable text, native production where the record actually requires it (spreadsheets, presentations, source code), and slip-sheeting for withheld and redacted documents.
Expert-witness support
Where the collection or production method is challenged, GDF provides the technical record and, where retained for it, expert testimony on the underlying method.
Evidence commonly reviewed
Evidence reviewed
- Chain-of-custody records for every collected source
- Collection logs (tool version, target, hash) for every image
- Processing manifests with dedup and near-dup counts
- Load-file specifications and production manifests
- Audit-log evidence for every hosted-review access event
What you receive
Deliverables
- Preservation notice templates aligned to Rule 26(f) practice
- Collection reports usable as exhibits to a Rule 26 filing
- Processed data loaded to the review platform of record
- Production sets in the form the receiving party accepts
- Where required, an expert report on the collection or production method
Engagement workflow
How the engagement runs
Preservation
Preservation is scoped against the specific custodians and specific systems that carry the record, not a broad seizure of the client's environment. For Microsoft 365 tenants, Purview eDiscovery holds are placed and the M365 unified audit log is preserved before rotation. For Google Workspace, Vault holds are placed with matching retention. For Slack, admin retention is set for the relevant channels and DMs. For endpoint EDR products, the retention window and export path are confirmed before the retention window closes on the events of interest. The preservation notice, the tenant-side hold configuration and the confirmation of hold are all captured so the record is defensible.
Collection
Collection is performed with defensible tools and a chain-of-custody record for every source. Endpoint collections use forensic imaging with cryptographic hash verification. Cloud collections use the tenant-side eDiscovery export path (Purview, Vault, Slack Discovery, Zoom compliance) with the API request and response captured for the record. Mobile collections use forensic tooling that preserves the source device and produces a hashed image of the extracted data. Where a specific source is unusual (a bespoke SaaS platform, a line-of-business application without a documented export path), the collection method is documented before the fact and reviewed with counsel.
Processing
Processing runs the collected data through a defensible pipeline: file identification, text and metadata extraction, dedup and near-dup analysis, threading of email conversations, and language identification. Processing manifests record what was ingested, what was excluded and why, and what was promoted to review. Where the ESI protocol specifies exception handling (encrypted containers, corrupt files, unusual formats), the exceptions are logged and reported to counsel rather than silently dropped.
Review support
Review is generally hosted on a platform of record chosen by counsel (Relativity, Everlaw, DISCO, Reveal, Nextpoint). GDF hosts the data on the platform, configures searches and workflows to counsel's specification, and produces workspace access reports and audit logs so the record of who accessed what and when is preserved. Where technology-assisted review (TAR/CAL) is used, the training methodology and the validation statistics are captured for the record.
Production
Production is prepared in the form the receiving party actually accepts: image and native production sets with matching load files, Bates-numbering and confidentiality endorsements, redactions applied and quality-controlled, and privilege logs prepared to counsel's specification. Production manifests are prepared so the receiving party can validate the delivery against the load file. Where a later privilege dispute reaches Rule 502(d), the production manifest and the review record support the good-faith review the rule contemplates.
Frequently asked
Common questions on SDNY eDiscovery
Can you defend the collection method at a Rule 37 hearing?
Yes. Where the collection method is challenged, GDF provides the technical record and, where retained for it, expert testimony on the method. Chain-of-custody, collection logs and hash evidence are prepared to be put in front of the court.
How do you handle mobile-device collections in SDNY?
For SDNY matters, mobile-device collections are commonly performed under a targeted protocol so only the relevant data is extracted. Where the device cannot be surrendered, a filtered logical extraction or a cloud-backup extraction can be used. The scope is set with counsel before collection begins.
Do you host on Relativity, or on your own platform?
GDF hosts on Relativity, Reveal, Everlaw, Nuix Discover, DISCO or on the receiving party's chosen platform. Where hosting on the receiving party's platform is preferred, GDF delivers the processed data in the form the receiving platform accepts.
How do you handle a rolling production schedule?
Rolling productions are scheduled against the Rule 26(f) discussion and the chambers' individual practices. Each rolling volume is delivered with its own production manifest, and the load file is written so the receiving party can ingest volumes incrementally.
Can you support a Special Master's ESI protocol?
Yes. Where a Special Master enters an ESI protocol, collection, processing and production workflows are designed to what the protocol actually requires and the technical record is prepared for reporting to the Special Master.
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189