Legal Discovery File Sharing: eDiscovery Best Practices
Manage eDiscovery file sharing efficiently. Handle large volumes of documents, maintain chain of custody, and meet discovery deadlines.
eDiscovery file sharing moves litigation document populations — typically 50,000 to 5 million documents per matter, totaling 50 GB to 2 TB after processing — between custodians, collection vendors, review platforms (Relativity, Everlaw, DISCO, Nuix Discover), co-counsel, and producing parties. The workflow runs through the EDRM model (Electronic Discovery Reference Model): identification, preservation, collection, processing, review, analysis, production, and presentation. Each phase has specific transfer and chain-of-custody requirements, and the Sedona Principles, Federal Rules of Civil Procedure 26 and 34, and case-specific ESI protocols govern how documents move.
The Load File: How Productions Actually Travel
A typical production isn't a zip of PDFs. It's a structured package:
- Native files in their original format (.pst email archives, .xlsx spreadsheets, .docx documents)
- Image files — TIFF (300 DPI black-and-white for text, color for embedded images) or PDF
- Load files — Concordance DAT or CSV metadata files with one row per document
- Extracted text — per-document .txt files with full-text searchable content
- Opticon OPT files — describe the TIFF page-to-document relationships
A production might contain 100,000 documents producing 800,000 pages across 50,000 TIFFs and 100,000 natives. Total size: 400-800 GB. Transfer via web tool is impractical at this scale.
For these transfers, the industry uses:
- Secure FTP over TLS with client certificates
- Dedicated eDiscovery transfer platforms — Relativity's direct-transfer features, Nuix's workflow tools
- Physical media — encrypted external hard drives shipped via bonded courier
- Cloud-to-cloud — if both parties use Relativity in the same Microsoft Azure region, direct copy is possible
ESI Protocols: Written Agreements That Govern Everything
A Meet and Confer under FRCP 26(f) produces an ESI Protocol. Well-drafted ESI Protocols specify:
- Data sources and custodian scope
- Preservation obligations and trigger dates
- Production formats (native + OCR'd TIFF + load file, fields to include)
- De-duplication methodology (MD5, SHA-1, or per-field)
- Privilege log format
- Clawback agreements per FRE 502(d)
- Production delivery method (FTP credentials, transfer platform, physical media)
- Search terms and validation protocol
Deviating from the ESI Protocol unilaterally — e.g., producing in a different format than agreed — creates sanctions exposure. Lay out the delivery method explicitly and stick to it.
Chain of Custody From Collection to Production
Rule 901(a) authenticity challenges start with chain of custody. For ESI, the chain typically documents:
- Collection — forensic image of custodian machine (dd, FTK Imager, EnCase Forensic Imager), email server export (Exchange PST, Google Vault), cloud collection from Microsoft 365 or Google Workspace
- Hashing at collection — MD5 and SHA-256 of the collection container
- Transfer to processing — hashes verified on receipt
- Processing — de-duplication, search term application, with logged parameters
- Review platform ingestion — reviewed by counsel with logged decisions
- Production assembly — redaction log, privilege log, production set built
- Delivery — transfer log with hash of production container, recipient acknowledgement
Each handoff produces a chain-of-custody entry. Vendors like Epiq, Consilio, KLDiscovery, and FTI Consulting maintain this documentation as part of their service.
Native Productions vs. TIFF With Load Files
ESI Protocol negotiations often hinge on native vs. image. Advantages and tradeoffs:
Native production:
- Preserves metadata naturally
- Easier for spreadsheets where formulas matter
- Smaller file size than TIFF
- Harder to redact — requires application-specific tools or conversion to PDF
- Harder to Bates number — stamp gets applied inconsistently
TIFF with load file:
- Consistent Bates stamping across document types
- Easier redaction (apply to image, not underlying file)
- Larger files — a 50-page .docx becomes 50 TIFFs
- Metadata extracted into load file, separate from the image
Modern practice often produces "native + image" — native files for specific types (typically spreadsheets, presentations, audio/video), TIFF for everything else.
Privilege Logs and Document Exclusion
Documents withheld for privilege go on a privilege log per FRCP 26(b)(5). Transfer-related privilege log entries include date, author, recipients, subject matter, and privilege basis. Metadata-only logs are increasingly common for email-heavy productions — log entries generated from the document metadata without requiring manual descriptions.
Clawback procedures from FRE 502(d) orders govern inadvertent privilege production. When privileged material gets produced by mistake:
- Notify opposing counsel promptly
- Request return or destruction
- Document the error and remediation
- Update the privilege log
- Amend production if appropriate
Transfer logs showing exactly what was produced and when the clawback was demanded support the clawback argument.
Review Platform Integration and Transfer
Review platforms expect ingestion in specific formats:
- Relativity — Overlay load files, native imports, direct S3 transfer for Azure-hosted instances
- Everlaw — zip of natives, Everlaw handles processing and imaging
- DISCO — similar to Everlaw, bulk upload via S3 with client credentials
- Nuix Discover — direct ingestion of forensic images in some configurations
The transfer from collection to processing to review, and from review to production, typically stays within one platform's ecosystem when possible. When platforms differ between firms or co-counsel, cross-platform transfers use the lowest common denominator (Concordance load files).
Small Productions and Ad-Hoc Discovery Transfers
Not every discovery transfer involves a production vendor. A 200-document production in a small employment case, a supplemental production of 15 emails found after the main production closed, expert report exhibits — these run through ad-hoc channels.
Requirements:
- Encryption in transit and at rest
- Audit log for proof of service
- Hash-based integrity verification
- Link expiration aligned with the ESI Protocol delivery window
HexaTransfer handles this shape of transfer: drop a production folder, encrypt client-side with AES-256-GCM, share a link, set expiration. Try it at hexatransfer.com — free, no account, 10 GB max. Send the access link to opposing counsel, log the transfer in the matter file, and serve a notice of production per the local rule.
International Discovery and Cross-Border Constraints
US-style discovery often conflicts with foreign data protection laws. GDPR Article 48 restricts data transfer "in response to an order or decision of a court" from outside the EU unless based on an international agreement. The Hague Evidence Convention provides a formal mechanism but is slow.
Practical patterns:
- Apply data minimization upfront — collect only what's responsive
- Pseudonymize or anonymize where the US case doesn't need specific individuals' identities
- Use EU-located review platforms for EU-origin data to keep processing on the right side of Chapter V
- Document the Aerospatiale balancing test analysis (Société Nationale Industrielle Aérospatiale v. US District Court, 482 U.S. 522) if proceeding outside Hague procedures
Blocking statutes — France's Loi n° 68-678, Switzerland's Article 271 of the Criminal Code — create criminal exposure for foreign-ordered disclosures without proper channels. Don't rush the collection.
Production Size, Segmentation, and Rolling Productions
A 2 TB production doesn't land in one file transfer. It comes in:
- Rolling productions — periodic batches per the ESI Protocol schedule (weekly, bi-weekly)
- Logical segmentation — by custodian, date range, or issue
- Physical segmentation — by media capacity (one 1 TB drive per batch)
Each batch ships with its own load file, production log, and hash verification. The receiving party processes batches as they arrive rather than waiting for the full production.
Post-Matter Retention and Disposal
After the case closes, discovery materials have their own retention schedule:
- Final productions — retained per engagement letter and legal hold considerations
- Work product derivatives — client's property typically; transferred or destroyed per client direction
- Vendor-held data — destroyed per the vendor agreement, typically 30-90 days after matter closure or per client instructions
- Outside counsel's copy — retained per firm's retention policy and state bar rules
Document the destruction. "We certify deletion of all matter-related data as of [date]" letters from vendors close the loop. Incomplete destruction creates exposure in later, unrelated matters — and sometimes in malpractice claims.
eDiscovery file sharing isn't a single tool choice. It's a multi-phase workflow with different tools at different scales, governed by the ESI Protocol, documented by chain of custody, and audited from collection through disposal. Plan the flow in advance, pick the right tool for each segment, and document every handoff.
Send large files securely with end-to-end encryption
Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.
Send a file