If a scheduled retention job deletes evidence during a legal hold, is that spoliation?
answer
- duty to preserve, not intent to destroy
- good faith covers only before the trigger
- reasonable steps is the standard
- prejudice cures versus intent sanctions
- restorable elsewhere changes everything
basics
~20 sYes. Spoliation is a failure to preserve, and intent is not required. Routine good-faith operation of a system excuses loss only before the duty attaches; afterwards, not suspending the job is itself the failure to take reasonable steps.
solid answer
~50 sYes, and the fact that nobody touched anything is not the defence people expect. Spoliation is the loss of material you had a duty to preserve; it does not require anyone to have intended it. The routine, good-faith operation of a system explains loss that happened *before* the duty attached; once it attaches, leaving the job running is the failure to take reasonable steps. In US federal civil litigation, Rule 37(e) governs this: if electronically stored information that should have been preserved is lost and cannot be restored or replaced, a court may order measures to cure the prejudice, and only on finding an intent to deprive the other side may it give an adverse-inference instruction, dismiss or enter default. Intent changes the severity of the sanction, not whether you are exposed. So the first move after a loss is hunting for a second copy.
go deeper
Know that spoliation means failing to preserve material you were obliged to keep, and that a scheduled job deleting it still counts. Nobody has to have intended the loss.
Explain where the routine good-faith operation principle applies and where it stops, and that intent affects the severity of the sanction rather than whether a failure occurred.
Show the response instinct: hunt for restorable second copies, quantify what was actually lost, and diagnose the scoping defect that let a custodian-shaped hold miss machine-generated telemetry.
Own the tradeoff between an over-broad hold that carries storage, review and data-minimisation costs and a narrow one that misses a job, and make sure someone is accountable for each suspended mechanism.
## Spoliation is a failure, not an act Spoliation is the destruction, alteration or loss of material a party had a duty to preserve. Candidates often hear the word as a synonym for shredding documents, and answer that an automated job cannot be spoliation because nobody decided to delete anything. That is the wrong shape. The duty is to *preserve*; the machinery in your estate deletes by default; therefore not stopping the machinery is the omission that causes the loss. The question a court asks is not "who pressed delete" but "what reasonable steps did you take once you knew". ## Where the good-faith idea really applies There is a genuine principle that the routine, good-faith operation of an electronic information system is not culpable: logs age out, mailboxes purge, backups expire, and no organisation is expected to keep everything forever on the off-chance. That principle protects loss that happened **before** the preservation duty attached. It evaporates the moment litigation is reasonably anticipated, because from then on the very thing that made the deletion routine, namely that it runs automatically and nobody has to think about it, is what you were supposed to think about. ## The sanction ladder, and where intent enters In US federal civil litigation the controlling text is Federal Rule of Civil Procedure 37(e), as amended in 2015. Its structure is worth knowing because it is the source of most of the confusion: - it applies only to electronically stored information that **should have been preserved** in the anticipation or conduct of litigation - it applies only where that information is **lost because a party failed to take reasonable steps** to preserve it - it applies only where the information **cannot be restored or replaced** through additional discovery - on finding prejudice to another party, the court may order measures no greater than necessary to cure it - **only** on finding that the party acted with the intent to deprive another party of the information's use may the court presume the information was unfavourable, instruct a jury that it may or must so presume, dismiss the action or enter a default judgment So the honest answer to "nobody meant to" is: correct, and that is why you are unlikely to face an adverse-inference instruction. You may still face curative measures, cost orders and, in practice, a witness having to explain on the record that the company was told to preserve and left the deletion running. Other jurisdictions frame it differently, but the direction of travel is the same everywhere: negligence reduces the sanction, it does not remove the exposure. ## Restorable is the escape hatch, so look first Because the rule bites only when the material cannot be restored or replaced, the first response to a discovered deletion is a hunt for secondary copies rather than a confession of hopelessness. A four-month-old VPN session record deleted from the object archive may still exist in the SIEM's searchable index, in a backup of the archive, in the firewall's own local buffer, in a flow record from a different sensor, in a case note that quoted it, or in the partner's copy of the same session from their end of the tunnel. Document the search as carefully as the loss. ## Why the job kept running: custodians versus systems The usual mechanism is not defiance, it is scope. A hold drafted as a list of people binds mailboxes and personal drives, and modern mail platforms honour it well: a mailbox-level hold keeps copies even when a user deletes items and even when a retention policy tries to purge them. Machine-generated telemetry has no custodian. Nobody's name is attached to a bucket lifecycle rule with a ninety-day expiry, so nobody was notified, so it ran. Rewriting the hold to name systems, date ranges, the specific job that would destroy the material and an owner who confirms suspension is the durable fix, and stating that in an interview shows you understand the failure rather than just its label. ## Over-preservation is not free either The reflex answer, "freeze absolutely everything", carries its own costs: storage, the burden of reviewing it all in discovery, and holding personal data longer than your own minimisation commitments allow. Scope narrowly and precisely, but err towards preserving where you are unsure, because an over-broad hold is an argument and a destroyed record is not.
- Does it help that the deleted logs might have exonerated us?No. You cannot argue the content of material you failed to preserve, and courts do not resolve that uncertainty in favour of the party that lost it. The realistic argument is about prejudice: showing the same facts are provable from surviving sources.
- The mailboxes were preserved but the log archive expired. Why?Because the hold was scoped to custodians. Mail platforms honour a mailbox-level hold against user deletion and retention purges, but a storage lifecycle rule belongs to no person, so nobody was notified. Rescope the hold to name systems, jobs, date ranges and an owner per job.
- Can restoring the logs from a backup make the problem go away?It removes the main risk. The rule bites only where the information cannot be restored or replaced, so a successful restore turns a preservation failure into a documented near miss. Record how you found and validated the second copy.
saying these in an interview costs you the question
- Says automated deletion cannot be spoliation because nobody intended it
- Thinks only deliberate destruction is sanctionable at all
- Believes an adverse-inference instruction is the only possible sanction
- Argues the deleted data would have helped their own side anyway
- Assumes the mail platform's hold also covered the log archive