{"site":{"name":"Koji","description":"AI-native customer research platform that helps teams conduct, analyze, and synthesize customer interviews at scale.","url":"https://www.koji.so","contentTypes":["blog","documentation"],"lastUpdated":"2026-08-03T05:03:54.301Z"},"content":[{"type":"documentation","id":"0f15a4a8-ba07-497c-8465-186202c07349","slug":"research-data-legal-hold-ediscovery","title":"Legal Hold and E-Discovery for Customer Research Data","url":"https://www.koji.so/docs/research-data-legal-hold-ediscovery","summary":"A legal hold suspends routine deletion of records that may be relevant to litigation. The duty to preserve is triggered when litigation is reasonably anticipated — typically well before a complaint is filed — and under FRCP 37(e) sanctions apply only where that duty existed and reasonable steps were not taken. Customer research generates highly discoverable material: interview transcripts and recordings, screener and consent records, structured question responses, analysis notes, and the report conclusions themselves, which can be read as evidence of what a company knew and when. A hold overrides retention schedules and auto-deletion, and GDPR Article 17(3)(e) provides the lawful basis to decline an erasure request where processing is necessary for the establishment, exercise or defence of legal claims. Research teams should be able to identify, freeze, and export all artifacts tied to a study or participant on demand.","content":"**A legal hold is an instruction to stop deleting. It overrides your retention schedule, your auto-deletion settings, and your instinct to tidy up — and the duty to issue one starts when litigation becomes reasonably foreseeable, not when a complaint arrives.** For research teams that means the interview you were about to purge under a 12-month retention policy may need to survive for years, and the tooling decision that matters is whether you can find and freeze it at all.\n\nThis guide is written for ResearchOps and research leaders working with legal counsel. It is not legal advice — scope, triggers, and obligations vary by jurisdiction and by matter, and your counsel decides all three.\n\n## Why research data is a discovery target\n\nProduct and customer research produces exactly the kind of record litigators look for: dated, first-person, and written before anyone was defending a position.\n\n| Artifact | Why it matters in discovery |\n|---|---|\n| Interview transcripts | Verbatim customer statements about a defect, harm, or promise |\n| Audio and video recordings | The primary record; consent status is often contested alongside it |\n| Screener and intake responses | Establishes who was recruited and what they were told |\n| Consent records | Central to any privacy or recording-law claim |\n| Structured question responses | Quantified, timestamped evidence of prevalence |\n| Analysis notes and tags | Shows how the organisation interpreted what it heard |\n| Research reports and readouts | Contemporaneous evidence of corporate knowledge and its date |\n| Slack or email threads about findings | Often the most damaging, and the most often forgotten |\n\nThe last two rows are why research teams get pulled into matters they had no idea they were part of. A usability report noting that 8 of 12 participants missed a safety disclosure is not just an insight; in a product-liability matter it is a document establishing notice.\n\n## What triggers the duty to preserve\n\nThe duty attaches when litigation is **pending or reasonably anticipated**. In practice, the triggers a research team should escalate include:\n\n- A demand letter, claim, or notice of arbitration\n- A regulatory inquiry or information request\n- A serious internal complaint or whistleblower report touching a product area you research\n- A decision by your own organisation to bring a claim\n- A pattern of customer complaints that legal is already tracking\n\nFRCP 37(e) is important to understand precisely: **it does not create a duty to preserve.** It applies only where a duty already existed and in-scope electronically stored information was lost because reasonable steps were not taken. That framing has two consequences. First, information lost before the duty arose is not covered — routine deletion under a documented schedule is defensible right up until the trigger. Second, courts assess \"reasonable steps\" in context, explicitly considering the routine, good-faith operation of an electronic information system and the proportionality of preservation efforts to the matter and the party's resources.\n\nWhich is to say: a documented, consistently applied retention schedule is your protection, and an ad-hoc one is your exposure.\n\n## The sanctions ladder, and why intent is the hinge\n\nRule 37(e) sets out two tiers once in-scope ESI is lost and cannot be restored or replaced:\n\n1. **On a finding of prejudice** to another party, the court may order measures no greater than necessary to cure that prejudice — additional discovery, cost-shifting, or permission to present evidence about the loss.\n2. **Only on a finding that the party acted with intent to deprive** another party of the information's use may the court presume the lost information was unfavourable, instruct the jury that it may or must so presume, dismiss the action, or enter default judgment.\n\nThe severe remedies require intent. That is precisely why the *process* is the deliverable: a dated hold notice, a documented scope, a record of which systems were frozen, and evidence that auto-deletion was suspended are what separate an unfortunate gap from an inference of bad faith.\n\n## Scoping a hold across research systems\n\nA hold notice that says \"preserve all research documents\" is unactionable. Scope it along four axes:\n\n- **Custodians** — the researchers, PMs, designers, and analysts who touched the topic. Include people who have since changed teams.\n- **Systems** — your research platform, repository, transcription tools, cloud storage, note-taking apps, ticketing, and messaging. Research data leaks into personal Drive folders more than anyone admits.\n- **Date range** — usually open-ended forward from a start date, since new research on the same topic falls in scope too.\n- **Subject matter** — the product area, feature, cohort, or claim. Be concrete enough that a researcher can answer \"is my study in scope?\" without emailing legal.\n\nThen do the thing most teams skip: **write down what you found and where.** A preservation memo listing each system, who searched it, on what date, and with what query is the single most useful artifact you can produce, and it is nearly impossible to reconstruct a year later.\n\n### The operational checklist\n\n1. Acknowledge the hold notice in writing, with a date.\n2. Suspend automated deletion for in-scope studies — this is the step with the shortest fuse.\n3. Suspend routine participant-data purges for in-scope participants only.\n4. Freeze the analysis layer, not just the raw data: tags, notes, and report versions.\n5. Export a preservation copy in a stable format and store it under access control.\n6. Notify custodians individually and confirm receipt.\n7. Log the whole thing.\n8. Re-issue reminders periodically; holds routinely outlast the people who received them.\n\nStep 4 is the one researchers underestimate. If your repository lets someone re-tag or edit a report in place, the version that mattered may already be gone. Preserve the readout as it existed, not as it currently reads.\n\n## When a hold collides with privacy obligations\n\nThis is the genuine hard case, and the one that paralyses teams. A participant submits a GDPR erasure request for data that is under an active legal hold. Deleting breaches the hold; refusing appears to breach the GDPR.\n\nIt does not. **Article 17(3)(e) states that the right to erasure does not apply to the extent processing is necessary for the establishment, exercise or defence of legal claims.** That is the lawful basis for declining, and it exists precisely for this situation.\n\nHandle it properly:\n\n- Apply the exception **only to the data actually within the hold's scope** — erase everything else the request covers.\n- Tell the individual that their request has been restricted, on what basis, and that it will be revisited. Silence is what turns a lawful refusal into a complaint.\n- Document the decision, the scope, and the approver.\n- Diary the request against the hold so it is honoured automatically on release.\n- Remember that Article 5(1)(e) storage limitation still applies to everything *outside* the hold. A hold on one matter is not a licence to stop deleting generally.\n\nSimilar carve-outs exist in other regimes — US state privacy laws generally permit retention necessary to exercise or defend legal claims — but the precise wording and scope differ, so confirm with counsel for each jurisdiction you operate in.\n\n## Records management: the boring work that makes holds possible\n\nYou cannot freeze what you cannot find. Three habits make holds tractable:\n\n- **A research records inventory.** One list: every system holding research data, its owner, what lives there, and its default retention. Most teams discover three systems they had forgotten during their first real hold, at exactly the wrong moment.\n- **A retention schedule with categories, not one global setting.** Raw recordings, transcripts, structured responses, consent records, and published reports usually warrant different periods. Consent records typically need to outlive the recordings they authorise.\n- **Consistent study metadata.** Product area, cohort, date, and legal-basis tags recorded at study creation are what make \"find everything about the checkout flow from 2025\" a query instead of an archaeology project.\n\n## How Koji supports preservation and production\n\nKoji is built so that a hold is a scoping exercise rather than a database dump.\n\n- **Everything is tied to a study and an interview record.** Transcripts, structured responses, and generated reports hang off the study they belong to, so a hold can be scoped by study, date range, or participant rather than by exporting everything and sorting later.\n- **Structured questions produce machine-readable evidence.** Koji's six [structured question types](/docs/structured-questions-guide) — open_ended, scale, single_choice, multiple_choice, ranking, and yes_no — mean prevalence claims are backed by discrete, timestamped fields instead of by someone's summary of a call. In a dispute about what the research actually showed, that distinction is worth a great deal.\n- **Consent and intake are captured with the interview**, not in a separate spreadsheet that has to be reconciled under time pressure. See [Intake Forms and Consent](/docs/intake-forms-and-consent).\n- **Export produces a stable preservation copy.** You can export study data — transcripts, structured responses, and reports — for storage in your own controlled environment, which is what a preservation copy needs to be.\n- **Workspace roles are explicit.** Koji workspaces have three roles — owner, admin, and member — so you can state who had access to what, a question that comes up in nearly every discovery dispute about a research system.\n- **Analysis is generated from the transcript, not typed over it.** Because Koji's AI produces reports directly from the interview record, the chain from customer statement to reported finding stays intact and reviewable. Traditional workflows — a moderator's memory, a Google Doc of notes, a deck assembled a week later — break that chain at three points, and every break is a place for an opposing party to argue the finding was constructed rather than observed.\n\nThe practical benefit compounds with volume. A team running continuous AI-moderated research has hundreds of consistently structured interview records rather than a decade of inconsistently named recordings in shared drives — which turns a hold from a multi-week fire drill into a scoped export.\n\n## Releasing a hold\n\nHolds end, and they should end deliberately:\n\n1. Written release from counsel, dated.\n2. Confirm no other matter covers the same records before resuming deletion.\n3. Resume normal retention and process the backlog of deferred deletions.\n4. Fulfil any privacy requests that were restricted during the hold — this is the step that gets forgotten, and it converts a defensible refusal into a live complaint.\n5. Record the release in the same log as the hold.\n\nHolds that are never released quietly become a policy of indefinite retention, which is itself a privacy and security liability. Closing them out is part of the job.\n\n## Related Resources\n\n- [Research Data Retention and Deletion](/docs/research-data-retention-deletion) — the schedule a hold suspends\n- [GDPR-Compliant AI User Research](/docs/gdpr-compliant-ai-user-research) — lawful basis, erasure, and storage limitation\n- [Interview Recording Consent Laws](/docs/interview-recording-consent-laws) — consent records are usually the first thing requested\n- [Intake Forms and Consent](/docs/intake-forms-and-consent) — capturing consent with the interview record\n- [Enterprise Security for AI Research Platforms](/docs/enterprise-security-ai-research-platforms) — access control and audit expectations\n- [Research Repository Guide](/docs/research-repository-guide) — findability is what makes preservation possible\n- [Structured Questions Guide](/docs/structured-questions-guide) — machine-readable evidence beats summarised notes\n\n## Frequently asked questions\n\n**What triggers a legal hold on research data?**\nThe duty to preserve attaches when litigation is pending or reasonably anticipated — which is usually well before a complaint is served. A demand letter, a regulatory inquiry, a serious internal complaint, or a decision by your own company to sue someone can all trigger it. FRCP 37(e) does not create the duty; it governs the consequences when material that should have been preserved is lost.\n\n**Are interview transcripts and recordings discoverable?**\nGenerally yes. Interview transcripts, audio recordings, screener responses, consent records, structured question data, analysis notes, and the resulting research reports are all electronically stored information. Research reports are particularly consequential because they can be read as contemporaneous evidence of what the company knew about a problem and when it knew it.\n\n**Does a legal hold override our data retention schedule?**\nYes. A legal hold suspends routine deletion for the records within its scope, including automated deletion configured in your research tools. Continuing to auto-delete in-scope material after a hold is issued is the most common route to a spoliation finding, because the deletion is documented and dated by the system itself.\n\n**What happens if we delete research data that was under a legal hold?**\nUnder FRCP 37(e), if lost ESI cannot be restored or replaced, a court may order measures no greater than necessary to cure the prejudice. If it finds the party acted with intent to deprive another party of the information, it may instruct the jury to presume the lost information was unfavourable, or dismiss the action or enter default judgment. The severe sanctions turn on intent, which is why documented, good-faith hold procedures matter so much.\n\n**How do I handle a GDPR deletion request during a legal hold?**\nArticle 17(3)(e) provides that the right to erasure does not apply where processing is necessary for the establishment, exercise or defence of legal claims. You can decline the erasure for the specific data within the hold's scope, but you should document the basis, limit the exception to the data actually needed, tell the individual their request has been restricted rather than ignored, and honour it once the hold is released.\n\n**Can I export everything tied to one participant from Koji?**\nYes. Koji lets you export study data — transcripts, structured question responses, and generated reports — and interview records are tied to the study and participant they belong to, so a hold or a subject-access request can be scoped to the specific study, date range, or participant rather than requiring a full-database dump.","category":"Research Operations","lastModified":"2026-08-02T03:16:23.071438+00:00","metaTitle":"Legal Hold & E-Discovery for Research Data: A ResearchOps Guide","metaDescription":"A practical guide to legal holds on customer research data: what triggers the duty to preserve under FRCP 37(e), which research artifacts are discoverable, how a hold overrides auto-deletion, and how GDPR Article 17(3)(e) resolves the erasure conflict.","keywords":["legal hold research data","e-discovery user research","litigation hold interview transcripts","preserving research records","FRCP 37(e) research","records management research data","research data subpoena","spoliation research"],"aiSummary":"A legal hold suspends routine deletion of records that may be relevant to litigation. The duty to preserve is triggered when litigation is reasonably anticipated — typically well before a complaint is filed — and under FRCP 37(e) sanctions apply only where that duty existed and reasonable steps were not taken. Customer research generates highly discoverable material: interview transcripts and recordings, screener and consent records, structured question responses, analysis notes, and the report conclusions themselves, which can be read as evidence of what a company knew and when. A hold overrides retention schedules and auto-deletion, and GDPR Article 17(3)(e) provides the lawful basis to decline an erasure request where processing is necessary for the establishment, exercise or defence of legal claims. Research teams should be able to identify, freeze, and export all artifacts tied to a study or participant on demand.","aiPrerequisites":["Familiarity with your organisation's research data retention schedule","Basic understanding of participant consent and privacy obligations"],"aiLearningOutcomes":["Recognise when the duty to preserve research data is triggered","Identify which research artifacts are discoverable","Write and scope a legal hold notice covering research systems","Suspend auto-deletion without breaking privacy commitments","Handle a GDPR erasure request that collides with an active hold","Release a hold and resume normal retention safely"],"aiDifficulty":"advanced","aiEstimatedTime":"12 min"}],"pagination":{"total":1,"returned":1,"offset":0}}