eDiscovery: how to leverage electronic evidence in an internal investigation
Emails, messages, documents: eDiscovery structures the collection and analysis of electronic evidence in an internal investigation, from data preservation to evidence production.


In any internal investigation — whether it involves fraud, harassment or a conflict of interest — reconstructing the facts relies on the traces employees leave behind. Today, those traces are overwhelmingly electronic: emails, instant messages, shared documents, files stored in the cloud. eDiscovery refers precisely to the practice of identifying, collecting and exploiting this digital evidence. Without this structured approach, investigators risk missing decisive elements.
What is eDiscovery?
eDiscovery (short for electronic discovery) refers to the process of identifying, collecting, preserving and analyzing electronic evidence in the context of legal proceedings or an internal investigation. Unlike a simple manual search in a mailbox, eDiscovery relies on specialized tools capable of processing massive volumes of data, detecting relevant documents and guaranteeing their integrity throughout the process.
In the context of an internal investigation, eDiscovery makes it possible to:
- Reconstruct an email thread between several employees suspected of harassment or collusion
- Track down successive versions of a document modified before a call for tenders
- Identify deleted communications on a professional instant messaging platform
- Cross-reference metadata (date, time, author, recipients) to establish a factual chronology
This transforms an often indigestible pile of files into a corpus of usable, admissible evidence.
The key stages of eDiscovery in an internal investigation
eDiscovery is not a simple mailbox export. It follows a rigorous protocol of five successive phases.
1. Identifying data sources
Before any collection, you must precisely map where potential evidence is located:
- Professional email (Outlook, Gmail, Exchange)
- Instant messaging (Teams, Slack, WhatsApp Business)
- File servers and cloud solutions (SharePoint, Google Drive)
- Local workstations (computers, external hard drives) or remote servers
This phase requires a deep understanding of the organization's information systems and the actual habits of the employees involved. Which tools do they use on a daily basis? Where do they store their sensitive documents?
2. Preserving data (legal hold)
Once the sources have been identified, it can be useful to freeze the data to prevent any modification or deletion, whether voluntary or accidental. This step, known as legal hold, consists of:
- Suspending automatic deletion policies (e.g. erasing emails after 90 days)
- Blocking write access to the accounts concerned
- Formally notifying data custodians (the employees concerned) of their obligation to preserve data
Failing to complete this step can lead to the irreversible loss of evidence, and even legal sanctions if the investigation leads to litigation.
3. Collecting data
Collection consists of physically extracting the preserved data while guaranteeing its technical and legal integrity. eDiscovery tools can generate a cryptographic hash, i.e. a unique digital fingerprint. This fingerprint proves that no data was altered between collection and analysis.
Two methods coexist:
- Remote collection (via dedicated solutions such as Purview or Vault)
- Physical collection (seizing hardware, forensic copying of hard drives)
The choice depends mainly on the organization's technical constraints and the sensitivity of the investigation.
4. Processing and reviewing data
This phase turns the raw collected volume into an analyzable corpus. It includes several technical operations:
- De-duplication: eliminating multiple copies of the same file
- Indexing: making content searchable by keywords, dates, authors
- Filtering: excluding irrelevant files (e.g. system files, automated emails)
- Metadata analysis: cross-referencing creation, modification and sending dates to establish a chronology
- Technology-Assisted Review (TAR): using artificial intelligence to automatically identify the most relevant documents in a corpus of several million files, notably through clustering and threading features.
The investigator can then carry out a document review: reading, annotating and tagging incriminating or exculpatory pieces of evidence, notably with tools such as Relativity, Logikcull or Nuix.
5. Producing and exploiting evidence
Once the corpus has been stabilized and analyzed, the retained documents are produced, i.e. formally extracted and presented in a usable format:
- PDF export with metadata
- Chronological or thematic reports
- Communication network visualizations (who writes to whom, how often)
These elements form the factual basis of the investigation. They can be used in an internal report, transmitted to the ethics committee, added to a disciplinary procedure file or, where applicable, produced before a judicial authority.
The leading platforms on the market
The eDiscovery market is dominated by professional solutions capable of processing massive volumes and guaranteeing the legal traceability of every operation. Here is an overview of the most widely used platforms:
Relativity
Relativity is the global reference for complex litigation and large-scale investigations. The platform offers advanced TAR (Technology-Assisted Review) features, communication network visualization and collaborative document review management. It is particularly popular with law firms and large corporations in the context of international litigation.
Nuix
Nuix stands out for its ability to process highly varied data sources — including exotic formats, encrypted messaging systems or corrupted archives. Its forensic analysis engine makes it a tool of choice for internal investigations requiring an advanced technical approach (reconstructing deleted files, analyzing damaged disks).
Logikcull
Logikcull targets the small and medium-sized investigation segment, with a self-service approach: users can upload, process and analyze their data without external technical intervention. The platform offers a simple, transparent pricing model based on the volume of data processed.
When should eDiscovery be used in an internal investigation?
eDiscovery is not systematically necessary for every investigation. Deploying it is justified when:
- The volume of data to analyze exceeds what a human can reasonably process manually
- The investigation concerns facts requiring a precise chronological reconstruction
- The case carries litigation risk (criminal proceedings, civil action, regulatory audit) requiring strict legal traceability
- Evidence is at risk of being destroyed or altered without immediate preservation measures
eDiscovery transforms the collection of electronic evidence into an industrialized, traceable process with stronger legal guarantees. Mastering its steps and tools enables internal investigators to reconstruct complex facts rigorously, detect concealed behavior and produce evidence usable before any authority — whether disciplinary, regulatory or judicial.
