Skip to main content
Promotional banner for the pentest readiness checklist
Category: Legal & Investigations

Electronically Stored Information

Also known as: ESI, ESI data, electronically stored information
Simply put

Electronically Stored Information (ESI) refers to any information that is created, changed, communicated, or kept in digital form. Common examples include word processing documents, emails, spreadsheets, images, sound and video recordings, and other data compilations. In legal disputes, ESI is often the material that one party must turn over to another during the discovery process.

Formal definition

Electronically Stored Information (ESI) is a term used prominently in the context of litigation and, in the United States, under the Federal Rules of Civil Procedure (FRCP), to describe information created, manipulated, communicated, or stored in digital form. According to available descriptions, ESI encompasses writings, drawings, graphs, charts, photographs, sound recordings, images, video recordings, computer-aided materials, and other data compilations. In practice, ESI is the category of digital material subject to identification, preservation, collection, and production during electronic discovery (e-discovery), whereby it is turned over from one party to another. The precise scope, procedural obligations, and treatment of ESI are jurisdiction- and rule-specific; the summary here reflects the FRCP-oriented and general legal usage present in the evidence, and specific requirements should be verified against the applicable primary rules and any governing court orders. Matters of legal interpretation regarding what constitutes discoverable ESI in a given matter require professional legal advice.

Why it matters

Electronically Stored Information sits at the intersection of compliance and litigation readiness because it defines the universe of digital material an organization may be required to identify, preserve, and produce when a dispute arises. In the United States, ESI is a recognized category under the Federal Rules of Civil Procedure, and the obligation to turn over relevant digital material to an opposing party during e-discovery can extend across emails, documents, spreadsheets, images, and audio or video recordings. Because so much of an organization's activity is now recorded in digital form, ESI often represents the bulk of the evidentiary record in a given matter.

The practical significance for governance and compliance functions lies in the need to manage this material before litigation is contemplated. Once a party is under a duty to preserve, the scope of ESI that must be retained and produced can be broad, and the treatment of that material is governed by applicable rules and any court orders. Failing to preserve or produce relevant ESI can expose an organization to procedural consequences, though the specific obligations and remedies are jurisdiction- and rule-specific and should be verified against the primary rules governing a particular matter.

Because the precise scope of discoverable ESI in any given case turns on legal interpretation, compliance and records-management professionals typically coordinate closely with legal counsel. What qualifies as relevant, proportionate, or subject to preservation is not a purely technical determination, and decisions about the handling of ESI in active or anticipated litigation require professional legal advice.

Who it's relevant to

General Counsel and Legal Teams
Legal functions are central to determining what ESI is relevant, discoverable, and subject to preservation in a given matter. Because what constitutes discoverable ESI often turns on legal interpretation and the applicable rules, these decisions require professional legal judgment and coordination with any governing court orders.
Compliance Officers
Compliance professionals are concerned with adherence to the rules and obligations that govern how digital material must be handled once a duty to preserve arises. They often coordinate with legal counsel to ensure that the organization's practices align with jurisdiction- and rule-specific requirements, which should be verified against primary sources.
Records and Information Management Professionals
Those responsible for managing digital records deal directly with the wide range of formats that fall within ESI, including emails, documents, spreadsheets, images, and audio and video recordings. Their practices influence whether relevant material can be identified, preserved, and produced when required.
Internal Auditors and Governance Professionals
Audit and governance stakeholders have an interest in whether the organization has structures in place to manage ESI-related obligations. Their role typically focuses on oversight of processes rather than on the legal determination of what specific material must be produced in a given dispute.

Inside ESI

Digital File Content
The substantive data held in electronic form, such as documents, spreadsheets, presentations, databases, and images, that may be relevant to a legal or regulatory matter.
Electronic Communications
Messages exchanged through channels such as email, instant messaging, collaboration platforms, and text or mobile messaging, which are commonly within the scope of ESI.
Metadata
Data about data, such as authorship, creation and modification timestamps, file paths, and system information, which can be relevant to authenticity and context but which varies by system and file type.
Structured and Unstructured Data
Structured data typically resides in databases and defined fields, while unstructured data includes free-form content such as documents and messages; both may fall within ESI depending on the matter.
Storage Locations and Media
The systems and repositories where information resides, which may include servers, endpoint devices, mobile devices, backup systems, and cloud-hosted environments; accessibility of these sources often varies.

Common questions

Answers to the questions practitioners most commonly ask about ESI.

Is Electronically Stored Information limited to email and office documents?
No. This is a common misconception. ESI typically encompasses a much broader range of data than email and word-processing files. In many legal and regulatory contexts, ESI extends to any information created, manipulated, communicated, stored, or best utilized in digital form, which can include databases, instant and collaboration platform messages, voicemail, social media content, metadata, log files, backup media, and data held by cloud or third-party providers. The precise scope treated as ESI in any given matter depends on applicable procedural rules and the facts at issue, and questions of what must be preserved or produced are matters of legal interpretation that warrant professional advice.
Does deleting a file mean the associated ESI no longer exists or is no longer discoverable?
Not necessarily, and treating deletion as permanent removal is a frequent misunderstanding. Deleted data often persists in backups, archives, system logs, cached copies, or on storage media until it is overwritten, and it may remain recoverable. Because of this, the existence of a deletion action does not by itself establish that ESI is beyond reach. Whether particular data remains accessible or must be preserved is fact- and jurisdiction-specific, and organizations should not assume routine deletion satisfies any preservation obligation without appropriate legal guidance.
How does an organization identify where its ESI resides?
Organizations commonly develop a data map or inventory that catalogs systems, repositories, data types, custodians, and third-party or cloud locations where information is created and stored. This exercise typically draws on input from IT, records management, business units, and legal or compliance functions. The completeness of such mapping varies by organization size and complexity, and it is often treated as an ongoing effort rather than a one-time task, since data environments change over time. What must be captured for a specific matter is a legal determination.
What is a legal hold, and how does it relate to ESI?
A legal hold, sometimes called a litigation hold or preservation notice, is a process by which an organization suspends normal disposition and takes steps to preserve information, including ESI, that may be relevant to anticipated or pending litigation, investigation, or regulatory inquiry. In practice this often involves notifying relevant custodians, suspending automatic deletion routines where appropriate, and documenting the steps taken. The timing, scope, and adequacy of a hold are matters of legal interpretation that depend on jurisdiction and circumstances and should be directed by counsel.
How can retention and disposition policies account for ESI?
Retention schedules and disposition policies typically address ESI alongside physical records, specifying how long different categories of information are kept and how they are defeasibly disposed of. Effective implementation often requires that these schedules be reflected in the configuration of systems, backups, and archives, and that routine disposition can be suspended when a preservation obligation arises. Applicable retention requirements vary by jurisdiction, sector, and the nature of the data, so schedules generally should be validated against the relevant legal and regulatory sources.
What role does metadata play in managing ESI?
Metadata, meaning data that describes other data such as authorship, creation and modification dates, or file properties, is often considered part of ESI and can be significant in establishing context, authenticity, or chronology. Because certain handling activities, such as copying or converting files, may alter or strip metadata, organizations frequently adopt collection and preservation practices intended to maintain metadata integrity where it may be relevant. The extent to which metadata must be preserved or produced is context-dependent and is generally a question for legal counsel.

Common misconceptions

ESI refers only to email and word processing documents.
ESI is generally understood to encompass a broad range of electronic information, which can include messaging platforms, databases, images, audio, video, system logs, and metadata, though the precise scope depends on the applicable rules and the specific matter.
Deleting a file permanently removes it from the scope of ESI.
Information that has been deleted may still be recoverable from backups, archives, or storage media, and preservation obligations often attach once litigation or investigation is reasonably anticipated; whether such data must be preserved or produced is a matter of applicable law and legal interpretation.
Metadata is not part of ESI and need not be preserved.
Metadata is frequently treated as a component of ESI and can be significant to authenticity and context, but its relevance, the obligation to preserve it, and the form of production vary by jurisdiction, matter, and the governing rules or agreements between parties.

Best practices

Implement a defensible information governance program that maps where electronic information resides, including endpoints, servers, mobile devices, and cloud-hosted environments, so relevant sources can be identified when needed.
Establish clear procedures for issuing and monitoring legal holds promptly once litigation or investigation is reasonably anticipated, coordinating between legal, compliance, and IT functions.
Maintain records retention and disposition schedules aligned with applicable legal and regulatory requirements, and suspend routine deletion for information subject to a preservation obligation.
Preserve metadata and original file characteristics where relevant, and document collection methods to support later questions of authenticity and chain of custody.
Engage qualified legal counsel and technical specialists early to address scope, accessibility, proportionality, and form of production, recognizing that these determinations are jurisdiction- and matter-specific.
Periodically test and validate preservation and collection processes, and verify specific obligations against the primary rules and governing authorities rather than relying on general convention.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide